Impact
The vulnerability is an unauthenticated SQL Injection in rtMedia plugin for WordPress, BuddyPress and bbPress. It allows an attacker to construct malicious input that bypasses the normal input validation and is passed directly to the database. If successful, the attacker could execute arbitrary SQL queries, leading to data disclosure, database corruption, or, in some configurations, remote code execution on the web server.
Affected Systems
Affected systems are installations of the rtCamp rtMedia plugin for WordPress, BuddyPress and bbPress with versions up to 4.7.11 inclusive. Any website that has not upgraded beyond these versions is vulnerable. The vulnerability does not affect WordPress core or other plugins, only rtMedia itself.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity; the absence of an EPSS score means no publicly available Exploit Probability data. The vulnerability is not listed in CISA's KEV catalog. It can be exploited over the web by making unauthenticated HTTP requests containing the crafted SQL payload. Because the flaw exists in a public-facing plugin, attackers with internet access to the target site can attempt exploitation without needing prior authentication.
OpenCVE Enrichment