Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

rtMedia for WordPress, BuddyPress and bbPress Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 16 vulnerability records associated with rtMedia for WordPress, BuddyPress and bbPress, published between 2014 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

16Total records
3Critical
4High
8Medium
1Low
0Informational
16Patched records
0Currently marked unpatched
2014-11-24First disclosure
2026-07-23Latest disclosure
10 of 16CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201411 records
201511 records
201622 records
202355 records
202422 records
202511 records
202644 records

Severity Breakdown

SeverityRecordsShare
Critical318.8%
High425%
Medium850%
Low16.3%

Vulnerability-Type Breakdown

SQL Injection

5 records31.3%

First: 2015. Latest: 2026.

Missing Authorization

5 records31.3%

First: 2023. Latest: 2026.

Arbitrary File Upload

3 records18.8%

First: 2016. Latest: 2023.

Other

1 record6.3%

First: 2014. Latest: 2014.

Cross-Site Scripting

1 record6.3%

First: 2016. Latest: 2016.

Information Disclosure

1 record6.3%

First: 2026. Latest: 2026.

Patch Status

Patched
16
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 4.7.11
  • 4.7.10
  • 4.7.9
  • 4.7.4
  • 4.6.19
  • 4.6.16
  • 4.6.15
  • 4.2.1
  • 3.10.2
  • 3.7.40
  • 3.10

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-4.7.10rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Unauthenticated SQL InjectionJuly 23, 20264.7.11High
*-4.7.10rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Authenticated (Subscriber+) SQL InjectionJuly 23, 20264.7.11Medium
*-4.7.9rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 - Missing AuthorizationApril 21, 20264.7.10Medium
*-4.7.8rtMedia for WordPress, BuddyPress and bbPress <= 4.7.8 - Unauthenticated Information ExposureFebruary 1, 20264.7.9Medium
4.7.0-4.7.3rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch FunctionDecember 12, 20254.7.4Low
*-4.6.18rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subscriber+) SQL InjectionApril 29, 20244.6.19Medium
*-4.6.18rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Contributor+) SQL Injection via rtmedia_gallery ShortcodeApril 22, 20244.6.19High
*-4.6.15rtMedia for WordPress, BuddyPress and bbPress <= 4.6.15 - Authenticated (Subscriber+) Arbitrary File UploadNovember 29, 20234.6.16High
*-4.6.15rtMedia for WordPress, BuddyPress and bbPress WordPress <= 4.6.15 - Authenticated (Admin+) Arbitrary File UploadNovember 29, 20234.6.16High
*-4.6.14rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization via export_settingsSeptember 6, 20234.6.15Medium
[*, 4.6.15)rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization to Sensitive Information ExposureSeptember 4, 20234.6.15Medium
[*, 4.6.15)rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization to Settings UpdateSeptember 4, 20234.6.15Medium
[*, 4.2.1)rtMedia for WordPress, BuddyPress and bbPress <= 4.2 - Arbitary File UploadDecember 21, 20164.2.1Critical
[*, 3.10.2)rtMedia for WordPress, BuddyPress and bbPress <= 3.10.1 - Cross-Site ScriptingJanuary 28, 20163.10.2Medium
[*, 3.7.40)rtMedia for WordPress, BuddyPress and bbPress < 3.7.40 - SQL InjectionApril 28, 20153.7.40Critical
*-3.9.5rtMedia for WordPress, BuddyPress and bbPress <= 3.9.5 - Local File InclusionNovember 24, 20143.10Critical

Selected source records

Latest Records

MediumCVE-2026-59551

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Authenticated (Subscriber+) SQL Injection

Published: July 23, 2026

Affected versions
*-4.7.10
Patched versions
4.7.11
Original Wordfence record
HighCVE-2026-59549

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Unauthenticated SQL Injection

Published: July 23, 2026

Affected versions
*-4.7.10
Patched versions
4.7.11
Original Wordfence record
MediumCVE-2026-40773

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 - Missing Authorization

Published: April 21, 2026

Affected versions
*-4.7.9
Patched versions
4.7.10
Original Wordfence record
MediumCVE-2026-25325

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.8 - Unauthenticated Information Exposure

Published: February 1, 2026

Affected versions
*-4.7.8
Patched versions
4.7.9
Original Wordfence record
LowCVE-2025-9218

rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function

Published: December 12, 2025

Affected versions
4.7.0-4.7.3
Patched versions
4.7.4
Original Wordfence record
MediumCVE-2026-15287

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subscriber+) SQL Injection

Published: April 29, 2024

Affected versions
*-4.6.18
Patched versions
4.6.19
Original Wordfence record
HighCVE-2024-3293

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode

Published: April 22, 2024

Affected versions
*-4.6.18
Patched versions
4.6.19
Original Wordfence record
HighCVE-2023-5939

rtMedia for WordPress, BuddyPress and bbPress WordPress <= 4.6.15 - Authenticated (Admin+) Arbitrary File Upload

Published: November 29, 2023

Affected versions
*-4.6.15
Patched versions
4.6.16
Original Wordfence record

Highest-Severity Records

Critical

rtMedia for WordPress, BuddyPress and bbPress <= 3.9.5 - Local File Inclusion

Published: November 24, 2014

Affected versions
*-3.9.5
Patched versions
3.10
Original Wordfence record
Critical

rtMedia for WordPress, BuddyPress and bbPress < 3.7.40 - SQL Injection

Published: April 28, 2015

Affected versions
[*, 3.7.40)
Patched versions
3.7.40
Original Wordfence record
Critical

rtMedia for WordPress, BuddyPress and bbPress <= 4.2 - Arbitary File Upload

Published: December 21, 2016

Affected versions
[*, 4.2.1)
Patched versions
4.2.1
Original Wordfence record
HighCVE-2024-3293

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode

Published: April 22, 2024

Affected versions
*-4.6.18
Patched versions
4.6.19
Original Wordfence record
HighCVE-2023-5931

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.15 - Authenticated (Subscriber+) Arbitrary File Upload

Published: November 29, 2023

Affected versions
*-4.6.15
Patched versions
4.6.16
Original Wordfence record
HighCVE-2026-59549

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Unauthenticated SQL Injection

Published: July 23, 2026

Affected versions
*-4.7.10
Patched versions
4.7.11
Original Wordfence record
HighCVE-2023-5939

rtMedia for WordPress, BuddyPress and bbPress WordPress <= 4.6.15 - Authenticated (Admin+) Arbitrary File Upload

Published: November 29, 2023

Affected versions
*-4.6.15
Patched versions
4.6.16
Original Wordfence record
MediumCVE-2026-59551

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Authenticated (Subscriber+) SQL Injection

Published: July 23, 2026

Affected versions
*-4.7.10
Patched versions
4.7.11
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory