{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rtmedia-for-wordpress-buddypress-and-bbpress--4.7.13/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rtcamp:rtmedia_for_wordpress_buddypress_and_bbpress:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89301"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rtMedia for WordPress, BuddyPress and bbPress (\u003c= 4.7.13)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","web-application","file-deletion"],"_cs_type":"advisory","_cs_vendors":["rtCamp"],"content_html":"\u003cp\u003eThe rtMedia for WordPress, BuddyPress, and bbPress plugin, developed by rtCamp, contains a critical vulnerability (CVE-2026-89301) affecting all versions up to and including 4.7.13. The vulnerability stems from insufficient file path validation within the plugin's 'process' function. An unauthenticated attacker can exploit this to perform arbitrary file deletion on the hosting server.\u003c/p\u003e\n\u003cp\u003eThe attack vector is enabled by the exposure of the 'rtmedia_upload_nonce' security token within frontend JavaScript. This token is rendered on any page utilizing the rtMedia gallery or upload shortcode. Because the plugin does not require prior authentication to retrieve this nonce, an attacker can harvest it from the public-facing HTML/JS and subsequently use it to invoke the vulnerable file processing routine. This poses a significant risk to site integrity, potentially allowing for the removal of critical configuration or site files.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to delete arbitrary files on the affected WordPress installation. This can result in complete site downtime, loss of functionality, or the removal of core security configurations, leading to a total loss of availability and integrity for the web application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the rtMedia for WordPress, BuddyPress and bbPress plugin to a version released after 4.7.13 immediately to patch the 'process' function path validation.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests directed at rtMedia processing endpoints that correspond with file deletion patterns.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to restrict access to the rtMedia upload and processing paths if an immediate plugin update is not feasible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T05:34:45Z","date_published":"2026-10-10T05:34:45Z","id":"https://feed.craftedsignal.io/briefs/2026-10-rtmedia-file-deletion/","summary":"The rtMedia for WordPress plugin contains a vulnerability in the 'process' function allowing unauthenticated attackers to delete arbitrary files on the server by leveraging exposed nonces.","title":"Unauthenticated Arbitrary File Deletion in rtMedia Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-rtmedia-file-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - RtMedia for WordPress, BuddyPress and BbPress (\u003c= 4.7.13)","version":"https://jsonfeed.org/version/1.1"}