Impact
Unauthenticated SQL Injection in the rtMedia plugin for WordPress, BuddyPress, and bbPress allows an attacker to send specially crafted requests that are executed directly against the database. This flaw, identified as CWE-89, permits the execution of arbitrary SQL statements which can compromise sensitive data, modify or delete content. Based on the description, it is inferred that an attacker could potentially alter application data or exfiltrate information.
Affected Systems
The vulnerability affects installations of the rtCamp rtMedia for WordPress, BuddyPress and bbPress plugin version 4.7.10 or earlier on WordPress sites. All sites running these versions are susceptible unless the plugin has been upgraded to 4.7.11 or later.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as Critical. The unauthenticated nature of the vulnerability means any user who can reach the site’s web interface could potentially exploit it, making the attack vector relatively simple. The EPSS score is below 1%, indicating a very low current exploitation probability, yet the high severity suggests that it could be abused if discovered. The flaw is not listed on CISA’s KEV catalog. The likely attack path involves sending crafted HTTP requests to the vulnerable endpoint, resulting in execution of arbitrary SQL.
OpenCVE Enrichment