PT-2026-109728 · WordPress · Rtmedia

CVE-2026-105892

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rtMedia for WordPress, BuddyPress and bbPress versions prior to 4.7.14
Description rtMedia for WordPress, BuddyPress and bbPress buddypress-media contains a Path Traversal issue. This occurs when the software fails to properly limit a pathname to a restricted directory, potentially allowing access to files outside the intended folder.
Recommendations Update rtMedia for WordPress, BuddyPress and bbPress to version 4.7.14 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105892

Affected Products

Rtmedia