Sceawere

Vulnerability Detail

CVE-2026-105892UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Path Traversal in rtMedia

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
rtCamp Inc.
Product
rtMedia for WordPress, BuddyPress and bbPress
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.7.13.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-10T19:16:56.990Z",
  "pubdate": "2026-10-10T19:16:56.990Z",
  "executiveSummary": "The rtMedia for WordPress, BuddyPress, and bbPress plugin (buddypress-media) is susceptible to an Improper Limitation of a Pathname to a Restricted Directory vulnerability, classified as Path Traversal.\nThis vulnerability affects all versions of the product from n/a through 4.7.13.\nThe flaw enables an unauthenticated or authenticated attacker to escape the intended directory structure of the application by supplying malicious input containing directory traversal sequences (e.g., ../).\nSuccessful exploitation allows unauthorized access to sensitive files residing outside the web root or intended plugin directories, potentially leading to the disclosure of configuration files, credentials, or other critical system data.\nThe impact includes information disclosure, unauthorized file system access, and potential compromise of the underlying WordPress environment depending on the sensitivity of the exposed files.\nThe vulnerability represents a significant security risk, as it bypasses standard access control mechanisms governing file system interactions within the plugin.",
  "technicalDetails": "The vulnerability resides in the way rtMedia handles file path requests, failing to implement adequate sanitization or validation of input parameters used to construct file system paths.\nThe root cause is the insufficient neutralization of special characters and directory navigation sequences such as '../' within the input provided to the application's file processing functionality.\nWhen an attacker provides a crafted request containing these traversal sequences, the application fails to constrain the file access to the designated subdirectory or repository.\nThe attack flow initiates when the attacker targets a specific endpoint or parameter within rtMedia responsible for file retrieval or processing. By injecting directory traversal payloads, the attacker effectively instructs the underlying server-side script to resolve paths relative to the current directory but pointing upward into the file system hierarchy.\nBecause the plugin does not enforce strict path canonicalization or verify that the resulting absolute path resides within the expected sandbox environment, the underlying PHP process executes the file operation on the unintended path.\nThis behavior allows the attacker to traverse out of the plugin's upload directory and gain read access to arbitrary files that the web server user has permission to access, such as wp-config.php or other sensitive system files located on the host server.\nThe vulnerability is present in versions up to 4.7.13 and does not strictly require advanced privileges, as the lack of path validation impacts the file processing logic regardless of the user's role, provided the vulnerable endpoint is reachable.\nPost-exploitation impact includes the systematic retrieval of sensitive configuration data or system information, which can be further leveraged to facilitate secondary attacks, such as database infiltration or full site takeover."
}
CVE-2026-105892: Path Traversal in rtMedia (CRITICAL Severity, CVSS: 9.8) | Sceawere