{
 "id": "WPSEC-2026-0532",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0532/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0532/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0532/index.md",
 "title": "rtMedia for WordPress, BuddyPress and bbPress <= 4.7.13 - Authenticated (Subscriber+) Limited File Read and Deletion via 'files' Parameter",
 "description": "The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to server-side file read and deletion in versions 3.6.13 up to, and including, 4.7.13. This is due to the media upload handler accepting a 'files' parameter from the request and passing the server file path it contains to wp_handle_sideload() without validation. This makes it possible for authenticated attackers with subscriber-level access and above to have a readable file on the server copied into the public uploads directory and then deleted from its original location. Files must still pass WordPress's file type and content checks, which reject PHP files such as wp-config.php when the PHP fileinfo extension is available. On servers without fileinfo, wp-config.php can be read and deleted, which can lead to a full site takeover.",
 "plugin": {
  "slug": "buddypress-media",
  "name": "rtMedia for WordPress, BuddyPress and bbPress",
  "full_name": "rtMedia for WordPress, BuddyPress and bbPress",
  "wordpress_org": "https://wordpress.org/plugins/buddypress-media/",
  "advisories_url": "https://wpsec.com/vuln/plugin/buddypress-media/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/buddypress-media"
 },
 "type": "FILE DELETION",
 "cwe": [
  "CWE-73"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.6,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": "3.6.13",
    "from_inclusive": true,
    "to": "4.7.14",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 3.6.13 before 4.7.14"
  ]
 },
 "introduced_in": "3.6.13",
 "fixed_in": "4.7.14",
 "remediation": "Update to 4.7.14 or later.",
 "fix_released": "2026-10-06T12:29:49+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-06T19:05:40.824252+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0532/",
  "https://plugins.svn.wordpress.org/buddypress-media/tags/4.7.14/",
  "https://wordpress.org/plugins/buddypress-media/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/buddypress-media",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}