rtMedia for WordPress, BuddyPress and bbPress <= 4.7.13 - Authenticated (Subscriber+) Missing Authorization to Media Attribute and Post Modification via Media Edit

Medium 6.5 CWE-915Fixed in 4.7.14
ID
WPSEC-2026-0531
Plugin
rtMedia for WordPress, BuddyPress and bbPress (buddypress-media)
Affected
from 3.0 before 4.7.14
Remediation
Update to 4.7.14 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness
CWE-915
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
rtMedia for WordPress, BuddyPress and bbPress on WPSec AttackSurface
Fix released
Published

Description

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 4.7.13. This is due to the media edit handler accepting every media database column from the request through rtmedia_sanitize_object(), not checking permission on the target album, and not restricting when privacy may be changed. This makes it possible for authenticated attackers with subscriber-level access and above to change protected fields of their own media items, such as the author, group context, album, linked activity and linked WordPress post. By linking a media item to another post ID and then editing the media, they can overwrite the title and content of arbitrary posts and pages. They can also overwrite another user's activity entry, attach media to other users' albums or to groups they do not belong to, and change the privacy of group media or media held for moderation.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0