Skip to content
Threat Feed
high advisory

Unauthenticated Arbitrary File Deletion in rtMedia Plugin for WordPress

The rtMedia for WordPress plugin contains a vulnerability in the 'process' function allowing unauthenticated attackers to delete arbitrary files on the server by leveraging exposed nonces.

CVE search metadata

CVE search record: CVE-2026-89301. Severity: high. CVSS: 7.5. KEV: no. Product: rtMedia for WordPress, BuddyPress and bbPress (<= 4.7.13). Brief: Unauthenticated Arbitrary File Deletion in rtMedia Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-rtmedia-file-deletion/

The rtMedia for WordPress, BuddyPress, and bbPress plugin, developed by rtCamp, contains a critical vulnerability (CVE-2026-89301) affecting all versions up to and including 4.7.13. The vulnerability stems from insufficient file path validation within the plugin's 'process' function. An unauthenticated attacker can exploit this to perform arbitrary file deletion on the hosting server.

The attack vector is enabled by the exposure of the 'rtmedia_upload_nonce' security token within frontend JavaScript. This token is rendered on any page utilizing the rtMedia gallery or upload shortcode. Because the plugin does not require prior authentication to retrieve this nonce, an attacker can harvest it from the public-facing HTML/JS and subsequently use it to invoke the vulnerable file processing routine. This poses a significant risk to site integrity, potentially allowing for the removal of critical configuration or site files.

Impact

Successful exploitation allows unauthenticated remote attackers to delete arbitrary files on the affected WordPress installation. This can result in complete site downtime, loss of functionality, or the removal of core security configurations, leading to a total loss of availability and integrity for the web application.

Recommendation

Prioritized actions for security and infrastructure teams:

  • Update the rtMedia for WordPress, BuddyPress and bbPress plugin to a version released after 4.7.13 immediately to patch the 'process' function path validation.
  • Review web server access logs for anomalous POST requests directed at rtMedia processing endpoints that correspond with file deletion patterns.
  • Implement Web Application Firewall (WAF) rules to restrict access to the rtMedia upload and processing paths if an immediate plugin update is not feasible.

Immediate actions

Update rtMedia for WordPress, BuddyPress and bbPress to a patched version beyond 4.7.13.

IT Operations 24h

Mitigations

Patch plugin to version > 4.7.13

immediate IT Operations

CVE-2026-89301