Description

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media items associated with draft or private posts.

INFO

Published Date :

2025-12-13T04:31:26.133Z

Last Modified :

2025-12-15T15:47:54.693Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-9218 vulnerability.

Vendors Products
Bbpress
  • Bbpress
Buddypress
  • Buddypress
Rtcamp
  • Rtmedia
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact