Description
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is exploitable on any public page containing an rtMedia shortcode (e.g., [rtmedia_gallery]) when the rtmedia_shortcode GET parameter is set, because RTMediaQuery::query() merges $_REQUEST into the internal query while only validating top-level array keys, allowing the nested 'compare' subvalue to reach the vulnerable sink without authentication.
Published: 2026-09-12
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality compromise via SQL injection
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a time-based blind SQL injection that originates from the 'compare' parameter used in rtMedia’s internal query generation. Because the plugin does not properly escape or prepare this user-supplied input, an attacker can inject additional SQL into the underlying statement. This flaw is an injection weakness (CWE-89) that allows unauthenticated parties to read arbitrary data from the WordPress database, creating a significant risk to the confidentiality of site content and administrative credentials rather than providing code execution or service disruption.

Affected Systems

rtMedia for WordPress, BuddyPress and bbPress plugins up to and including version 4.7.11 are affected. Any WordPress installation that embeds an rtMedia shortcode such as [rtmedia_gallery] and passes the rtmedia_shortcode parameter in the query string is exposed. Sites using any WordPress, BuddyPress or bbPress environment controls, are vulnerable.

Risk and Exploitability

With a CVSS score of 7.5 the flaw is moderately severe, and the EPSS score of less than 1% indicates a very low observed exploitation likelihood; the vulnerability is not listed in CISA’s KEV and remote, requiring only that an attacker be able to construct a URL targeting a public page that includes an rtMedia shortcode. Successful exploitation would enable the existing query, allowing extraction of sensitive database information such as user credentials, content, or configuration data.

Generated by OpenCVE AI on September 15, 2026 at 18:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the rtMedia plugin to version 4.7.12 or later to eliminate the vulnerable query logic.
  • Apply a server-side filter or a security plugin that removes or sanitizes the 'compare' parameter from incoming requests before they reach rtMedia.
  • Restrict the use of rtMedia shortcodes to authenticated users or control their visibility through role-based settings so that external visitors cannot trigger the vulnerable code path.

Generated by OpenCVE AI on September 15, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Rtcamp
Rtcamp rtmedia For Wordpress, Buddypress And Bbpress
Wordpress
Wordpress wordpress
Vendors & Products Rtcamp
Rtcamp rtmedia For Wordpress, Buddypress And Bbpress
Wordpress
Wordpress wordpress

Sat, 12 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is exploitable on any public page containing an rtMedia shortcode (e.g., [rtmedia_gallery]) when the rtmedia_shortcode GET parameter is set, because RTMediaQuery::query() merges $_REQUEST into the internal query while only validating top-level array keys, allowing the nested 'compare' subvalue to reach the vulnerable sink without authentication.
Title rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 - Unauthenticated SQL Injection via 'compare' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Rtcamp Rtmedia For Wordpress, Buddypress And Bbpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-15T14:01:20.160Z

Reserved: 2026-07-21T15:15:26.548Z

Link: CVE-2026-16482

cve-icon Vulnrichment

Updated: 2026-09-15T13:27:01.965Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T08:16:23.797

Modified: 2026-09-15T15:17:13.610

Link: CVE-2026-16482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:45:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')