<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:rtcamp:rtmedia_for_wordpress_buddypress_and_bbpress:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3artcamprtmedia_for_wordpress_buddypress_and_bbpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 05:34:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3artcamprtmedia_for_wordpress_buddypress_and_bbpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Arbitrary File Deletion in rtMedia Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-10-rtmedia-file-deletion/</link><pubDate>Sat, 10 Oct 2026 05:34:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-rtmedia-file-deletion/</guid><description>The rtMedia for WordPress plugin contains a vulnerability in the 'process' function allowing unauthenticated attackers to delete arbitrary files on the server by leveraging exposed nonces.</description><content:encoded><![CDATA[<p>The rtMedia for WordPress, BuddyPress, and bbPress plugin, developed by rtCamp, contains a critical vulnerability (CVE-2026-89301) affecting all versions up to and including 4.7.13. The vulnerability stems from insufficient file path validation within the plugin's 'process' function. An unauthenticated attacker can exploit this to perform arbitrary file deletion on the hosting server.</p>
<p>The attack vector is enabled by the exposure of the 'rtmedia_upload_nonce' security token within frontend JavaScript. This token is rendered on any page utilizing the rtMedia gallery or upload shortcode. Because the plugin does not require prior authentication to retrieve this nonce, an attacker can harvest it from the public-facing HTML/JS and subsequently use it to invoke the vulnerable file processing routine. This poses a significant risk to site integrity, potentially allowing for the removal of critical configuration or site files.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to delete arbitrary files on the affected WordPress installation. This can result in complete site downtime, loss of functionality, or the removal of core security configurations, leading to a total loss of availability and integrity for the web application.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and infrastructure teams:</p>
<ul>
<li>Update the rtMedia for WordPress, BuddyPress and bbPress plugin to a version released after 4.7.13 immediately to patch the 'process' function path validation.</li>
<li>Review web server access logs for anomalous POST requests directed at rtMedia processing endpoints that correspond with file deletion patterns.</li>
<li>Implement Web Application Firewall (WAF) rules to restrict access to the rtMedia upload and processing paths if an immediate plugin update is not feasible.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>web-application</category><category>file-deletion</category></item></channel></rss>