Sceawere
Vulnerability Detail
CVE-2026-89301UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
rtMedia Arbitrary File Deletion Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- rtcamp
- Product
- rtMedia for WordPress, BuddyPress and bbPress
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the process function in all versions up to, and including, 4.7.13 This makes it possible for unauthenticated attackers to delete arbitrary safe files on the server.. The public nonce (rtmedia_upload_nonce) is emitted into frontend JavaScript on any page rendering the rtMedia gallery or upload shortcode, making it retrievable by unauthenticated visitors without any prior authentication or privileged action.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-10T05:16:40.403Z",
"pubdate": "2026-10-10T05:16:40.403Z",
"executiveSummary": "The rtMedia plugin for WordPress, BuddyPress, and bbPress contains a critical vulnerability involving insufficient file path validation, leading to arbitrary file deletion.\nThis vulnerability exists in all versions up to and including 4.7.13.\nThe flaw stems from improper sanitization of file paths within the process function, allowing unauthenticated remote attackers to trigger the deletion of sensitive files on the web server.\nThe attack vector is facilitated by the public exposure of the rtmedia_upload_nonce within the frontend JavaScript code whenever an rtMedia gallery or upload shortcode is rendered.\nBecause the nonce is retrievable by any unauthenticated visitor, no privileged session is required to execute the attack.\nSuccessful exploitation results in the unauthorized removal of arbitrary files accessible to the web server process, potentially leading to service disruption, configuration loss, or site compromise.\nThe risk is severe due to the ease of nonce retrieval and the lack of authentication required to invoke the vulnerable functionality.",
"technicalDetails": "The vulnerability originates in the process function of the rtMedia plugin, which handles file upload and management requests. The root cause is a failure to strictly validate user-supplied file paths or implement adequate directory traversal protection mechanisms before executing deletion operations.\nWhen a user triggers an action through the plugin's frontend, the application relies on a security token, the rtmedia_upload_nonce, to verify the intent of the request. However, this nonce is ubiquitously embedded in the frontend JavaScript source code on any page where the rtMedia gallery or upload shortcode is active. This design choice effectively renders the nonce public knowledge, bypassing the intended security purpose of cross-site request forgery protection.\nThe attack flow follows a predictable sequence: First, an unauthenticated attacker navigates to any public page hosting an rtMedia component to scrape the rtmedia_upload_nonce from the page source or JavaScript files. Second, the attacker crafts a malicious HTTP request that interacts with the vulnerable process function.\nBy manipulating the parameters sent to this function—specifically those responsible for file path identification—the attacker can force the server-side application to target files outside of the intended directory structure. Because the application lacks path sanitization, the server interprets the provided path directly, allowing for the deletion of any file that the web server user has the system-level permissions to remove.\nThe impact of this vulnerability is significant. An attacker can delete core WordPress configuration files such as wp-config.php, plugin files, or uploaded media assets. Removing wp-config.php, for instance, would force the application into a re-installation state or render the site inaccessible, resulting in a complete denial of service. The vulnerability is exploitable remotely over the network without any requirement for authenticated administrative access, making it a high-priority risk for any site utilizing the rtMedia plugin."
}