Description
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the process function in all versions up to, and including, 4.7.13 This makes it possible for unauthenticated attackers to delete arbitrary safe files on the server.. The public nonce (rtmedia_upload_nonce) is emitted into frontend JavaScript on any page rendering the rtMedia gallery or upload shortcode, making it retrievable by unauthenticated visitors without any prior authentication or privileged action.
Published: 2026-10-10
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized deletion of arbitrary files on the server
Action: Immediate Patch
AI Analysis

Impact

A weakness in the rtMedia plugin for WordPress allows an unauthenticated attacker to delete arbitrary files stored on the same server as the WordPress installation. The vulnerability stems from insufficient validation of the file path used during the sideload upload process, enabling the removal of any file that is considered "safe" by the plugin. Such deletions can compromise website integrity, lead to loss of media assets, and potentially alter critical configuration or data files, thereby affecting the availability and consistency of the site.

Affected Systems

All installations of the rtMedia plugin for WordPress, BuddyPress, and bbPress with versions up to and including 4.7.13 are affected. The plugin is distributed by rtcamp and is commonly used as a media management component within WordPress sites powered by BuddyPress or bbPress.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. While the EPSS score is not available, the vulnerability can be exploited by any user who can view a page that renders the rtMedia gallery or upload shortcode, because the public nonce (rtmedia_upload_nonce) is exposed in the page’s JavaScript. An attacker can then craft an upload request that uses the exposed nonce and supplies a malicious 'files[tmp_name]' parameter to trigger the deletion logic, enabling file removal without requiring authentication or elevated privileges. The vulnerability is not listed in CISA’s KEV catalog, but the straightforward exploitation path suggests that it could be abused in the wild.

Generated by OpenCVE AI on October 10, 2026 at 05:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade rtMedia to version 4.7.14 or later to remove the path validation flaw
  • If an upgrade is not immediately possible, restrict access to the upload endpoint so that only authenticated users with appropriate permissions can invoke it
  • Consider disabling or removing the public nonce from front‑end JavaScript to prevent unauthorized inclusion of the upload nonce in malicious requests

Generated by OpenCVE AI on October 10, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the process function in all versions up to, and including, 4.7.13 This makes it possible for unauthenticated attackers to delete arbitrary safe files on the server.. The public nonce (rtmedia_upload_nonce) is emitted into frontend JavaScript on any page rendering the rtMedia gallery or upload shortcode, making it retrievable by unauthenticated visitors without any prior authentication or privileged action.
Title rtMedia for WordPress, BuddyPress and bbPress <= 4.7.13 - Missing Authorization to Unauthenticated Limited File Read/Disclosure and Limited File Deletion via Sideload via 'files[tmp_name]' Parameter
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:49.111Z

Reserved: 2026-09-11T13:27:56.066Z

Link: CVE-2026-89301

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:40.403

Modified: 2026-10-10T05:16:40.403

Link: CVE-2026-89301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T05:30:09Z

Weaknesses