Impact
The rtMedia plugin for WordPress, BuddyPress and bbPress permits a logged‑in user to alter the privacy setting of another user’s activity and its attached media. Because the plugin validates only a nonce that is shared by all authenticated users and does not confirm ownership of the activity being modified, any subscriber‑level user can submit a request to change another user’s private activity to public or hide a public activity. This enables a loss of confidentiality and undermines the intended privacy controls of the site.
Affected Systems
WordPress sites running rtMedia for WordPress, BuddyPress and bbPress with version earlier than 4.7.12. The vulnerability is present for any installation that has the plugin activated and where subscriber or higher accounts exist. Verify the exact plugin version.
Risk and Exploitability
The CVSS base score of 4.2 indicates a moderate impact due to the lack of ownership checks. The EPSS score is below 1%, reflecting a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and no public exploitation has been reported. Because the flaw requires only that an attacker be logged in as a member with subscriber level or higher, the potential damage is limited to privacy exposure rather than privilege escalation or data theft. The overall risk is moderate, contingent upon the presence of vulnerable plugin versions on publicly accessible WordPress installations.
OpenCVE Enrichment