SQL Injection
5 records31.3%First: 2015. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 16 vulnerability records associated with rtMedia for WordPress, BuddyPress and bbPress, published between 2014 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 1 | |
| 2015 | 1 | |
| 2016 | 2 | |
| 2023 | 5 | |
| 2024 | 2 | |
| 2025 | 1 | |
| 2026 | 4 |
| Severity | Records | Share |
|---|---|---|
| Critical | 3 | 18.8% |
| High | 4 | 25% |
| Medium | 8 | 50% |
| Low | 1 | 6.3% |
First: 2015. Latest: 2026.
First: 2023. Latest: 2026.
First: 2016. Latest: 2023.
First: 2014. Latest: 2014.
First: 2016. Latest: 2016.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.7.114.7.104.7.94.7.44.6.194.6.164.6.154.2.13.10.23.7.403.10Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.7.10 | rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Unauthenticated SQL Injection | July 23, 2026 | 4.7.11 | High |
*-4.7.10 | rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Authenticated (Subscriber+) SQL Injection | July 23, 2026 | 4.7.11 | Medium |
*-4.7.9 | rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 - Missing Authorization | April 21, 2026 | 4.7.10 | Medium |
*-4.7.8 | rtMedia for WordPress, BuddyPress and bbPress <= 4.7.8 - Unauthenticated Information Exposure | February 1, 2026 | 4.7.9 | Medium |
4.7.0-4.7.3 | rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function | December 12, 2025 | 4.7.4 | Low |
*-4.6.18 | rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subscriber+) SQL Injection | April 29, 2024 | 4.6.19 | Medium |
*-4.6.18 | rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode | April 22, 2024 | 4.6.19 | High |
*-4.6.15 | rtMedia for WordPress, BuddyPress and bbPress <= 4.6.15 - Authenticated (Subscriber+) Arbitrary File Upload | November 29, 2023 | 4.6.16 | High |
*-4.6.15 | rtMedia for WordPress, BuddyPress and bbPress WordPress <= 4.6.15 - Authenticated (Admin+) Arbitrary File Upload | November 29, 2023 | 4.6.16 | High |
*-4.6.14 | rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization via export_settings | September 6, 2023 | 4.6.15 | Medium |
[*, 4.6.15) | rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization to Sensitive Information Exposure | September 4, 2023 | 4.6.15 | Medium |
[*, 4.6.15) | rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization to Settings Update | September 4, 2023 | 4.6.15 | Medium |
[*, 4.2.1) | rtMedia for WordPress, BuddyPress and bbPress <= 4.2 - Arbitary File Upload | December 21, 2016 | 4.2.1 | Critical |
[*, 3.10.2) | rtMedia for WordPress, BuddyPress and bbPress <= 3.10.1 - Cross-Site Scripting | January 28, 2016 | 3.10.2 | Medium |
[*, 3.7.40) | rtMedia for WordPress, BuddyPress and bbPress < 3.7.40 - SQL Injection | April 28, 2015 | 3.7.40 | Critical |
*-3.9.5 | rtMedia for WordPress, BuddyPress and bbPress <= 3.9.5 - Local File Inclusion | November 24, 2014 | 3.10 | Critical |
Selected source records
Published: July 23, 2026
Published: July 23, 2026
Published: April 21, 2026
Published: February 1, 2026
Published: December 12, 2025
Published: April 29, 2024
Published: April 22, 2024
Published: November 29, 2023
Published: November 24, 2014
Published: April 28, 2015
Published: December 21, 2016
Published: April 22, 2024
Published: November 29, 2023
Published: July 23, 2026
Published: November 29, 2023
Published: July 23, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.