{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rtmedia-for-wordpress-buddypress-and-bbpress--4.7.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rtcamp:rtmedia:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-16482"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rtMedia for WordPress, BuddyPress and bbPress (\u003c= 4.7.11)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["rtCamp"],"content_html":"\u003cp\u003eThe rtMedia for WordPress, BuddyPress and bbPress plugin (versions 4.7.11 and earlier) contains a critical security flaw identified as CVE-2026-16482. This vulnerability is a time-based blind SQL injection caused by insufficient input escaping and lack of parameterized queries within the RTMediaQuery::query() method. Attackers can exploit this by injecting malicious SQL statements into the compare parameter. Because the plugin incorrectly merges the $_REQUEST array into the internal query while only validating top-level keys, an unauthenticated attacker can supply nested subvalues that reach the vulnerable SQL execution sink. This is specifically exploitable on any publicly accessible WordPress page containing an rtMedia shortcode, such as [rtmedia_gallery], when the rtmedia_shortcode GET parameter is present. Successful exploitation permits unauthorized access to sensitive database contents, posing a high risk to the confidentiality of stored data.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a public-facing WordPress page containing an rtMedia shortcode (e.g., [rtmedia_gallery]).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET request targeting the identified page.\u003c/li\u003e\n\u003cli\u003eAttacker appends the rtmedia_shortcode parameter to the URL to trigger the vulnerable code path.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious payload into the compare parameter, formatted as a nested subvalue (e.g., compare[field]=value).\u003c/li\u003e\n\u003cli\u003eThe server-side RTMediaQuery::query() function receives the request and improperly merges the input into a database query.\u003c/li\u003e\n\u003cli\u003eThe backend SQL database processes the injected time-based command (e.g., SLEEP() or BENCHMARK()).\u003c/li\u003e\n\u003cli\u003eAttacker observes the differential in HTTP response time to confirm successful injection and exfiltrate data character-by-character.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to perform unauthorized database queries. This can lead to the full extraction of sensitive WordPress site data, including user credentials, configuration details, and private content, directly impacting the confidentiality of the affected organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the rtMedia for WordPress, BuddyPress and bbPress plugin to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eUse the provided Sigma rule to monitor web server logs for suspicious parameter patterns associated with this vulnerability.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block incoming GET requests containing recursive or nested parameter keys associated with SQL injection attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-12T09:18:58Z","date_published":"2026-09-12T09:18:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rtmedia-sql-injection/","summary":"The rtMedia for WordPress plugin is vulnerable to unauthenticated time-based blind SQL injection via the compare parameter, allowing sensitive database information extraction.","title":"CVE-2026-16482: Blind SQL Injection in rtMedia Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-rtmedia-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - RtMedia for WordPress, BuddyPress and BbPress (\u003c= 4.7.11)","version":"https://jsonfeed.org/version/1.1"}