Impact
A weakness in the rtMedia plugin for WordPress allows an unauthenticated attacker to delete arbitrary files stored on the same server as the WordPress installation. The vulnerability stems from insufficient validation of the file path used during the sideload upload process, enabling the removal of any file that is considered "safe" by the plugin. Such deletions can compromise website integrity, lead to loss of media assets, and potentially alter critical configuration or data files, thereby affecting the availability and consistency of the site.
Affected Systems
All installations of the rtMedia plugin for WordPress, BuddyPress, and bbPress with versions up to and including 4.7.13 are affected. The plugin is distributed by rtcamp and is commonly used as a media management component within WordPress sites powered by BuddyPress or bbPress.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. While the EPSS score is not available, the vulnerability can be exploited by any user who can view a page that renders the rtMedia gallery or upload shortcode, because the public nonce (rtmedia_upload_nonce) is exposed in the page’s JavaScript. An attacker can then craft an upload request that uses the exposed nonce and supplies a malicious 'files[tmp_name]' parameter to trigger the deletion logic, enabling file removal without requiring authentication or elevated privileges. The vulnerability is not listed in CISA’s KEV catalog, but the straightforward exploitation path suggests that it could be abused in the wild.
OpenCVE Enrichment