๐Ÿ” CVE Alert

CVE-2025-9218

LOW 3.7

rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media items associated with draft or private posts.

CWE CWE-862
Vendor rtcamp
Product rtmedia for wordpress, buddypress and bbpress
Published Dec 13, 2025
Last Updated Dec 15, 2025
Stay Ahead of the Next One

Get instant alerts for rtcamp rtmedia for wordpress, buddypress and bbpress

Be the first to know when new low vulnerabilities affecting rtcamp rtmedia for wordpress, buddypress and bbpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

rtcamp / rtMedia for WordPress, BuddyPress and bbPress
4.7.0 โ‰ค 4.7.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/68533b4c-1bdf-4104-a263-757b018af129?source=cve wordpress.org: https://wordpress.org/plugins/buddypress-media/#developers plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3386907/buddypress-media/tags/4.7.4/app/main/controllers/api/RTMediaJsonApi.php

Credits

Kenneth Dunn