Impact
The vulnerability is a time-based blind SQL injection that originates from the 'compare' parameter used in rtMedia’s internal query generation. Because the plugin does not properly escape or prepare this user-supplied input, an attacker can inject additional SQL into the underlying statement. This flaw is an injection weakness (CWE-89) that allows unauthenticated parties to read arbitrary data from the WordPress database, creating a significant risk to the confidentiality of site content and administrative credentials rather than providing code execution or service disruption.
Affected Systems
rtMedia for WordPress, BuddyPress and bbPress plugins up to and including version 4.7.11 are affected. Any WordPress installation that embeds an rtMedia shortcode such as [rtmedia_gallery] and passes the rtmedia_shortcode parameter in the query string is exposed. Sites using any WordPress, BuddyPress or bbPress environment controls, are vulnerable.
Risk and Exploitability
With a CVSS score of 7.5 the flaw is moderately severe, and the EPSS score of less than 1% indicates a very low observed exploitation likelihood; the vulnerability is not listed in CISA’s KEV and remote, requiring only that an attacker be able to construct a URL targeting a public page that includes an rtMedia shortcode. Successful exploitation would enable the existing query, allowing extraction of sensitive database information such as user credentials, content, or configuration data.
OpenCVE Enrichment