rtMedia for WordPress, BuddyPress and bbPress <= 4.7.13 - Authenticated (Subscriber+) Missing Authorization to Media Attribute and Post Modification via Media Edit
- ID
- WPSEC-2026-0531
- Plugin
- rtMedia for WordPress, BuddyPress and bbPress (buddypress-media)
- Affected
- from 3.0 before 4.7.14
- Remediation
- Update to 4.7.14 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Weakness
- CWE-915
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- rtMedia for WordPress, BuddyPress and bbPress on WPSec AttackSurface
- Fix released
- Published
Description
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 4.7.13. This is due to the media edit handler accepting every media database column from the request through rtmedia_sanitize_object(), not checking permission on the target album, and not restricting when privacy may be changed. This makes it possible for authenticated attackers with subscriber-level access and above to change protected fields of their own media items, such as the author, group context, album, linked activity and linked WordPress post. By linking a media item to another post ID and then editing the media, they can overwrite the title and content of arbitrary posts and pages. They can also overwrite another user's activity entry, attach media to other users' albums or to groups they do not belong to, and change the privacy of group media or media held for moderation.
References
- https://wpsec.com/vuln/WPSEC-2026-0531/
- https://plugins.svn.wordpress.org/buddypress-media/tags/4.7.14/
- https://wordpress.org/plugins/buddypress-media/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS