Input validation vulnerability in rtMedia for WordPress, BuddyPress and bbPress 3.7.18

The rtMedia for WordPress, BuddyPress and bbPress plugin is prone to a security vulnerability that can be exploited in versions up to and including 3.7.18. Attackers who have been authenticated are able to include and run any arbitrary file on the server by using the ‘template’ parameter. This can be used to bypass security measures, gain access to sensitive data, or even execute code in cases where images and other “safe” file types can be uploaded and included.

Detected in:

rtMedia for WordPress, BuddyPress and bbPress fixed vulnerable versions: >= * <= 3.9.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.