CVE Database /
CVE-2023-5931
CVE · High
CVE-2023-5931 — rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.16
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-5931
|
rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.16 |
Unrestricted Upload of File with Dangerous Type |
High
8.8
|
< 4.6.16
|
4.6.16 |
2023-11-29 |
—
|
CVE-2023-5931
The rtMedia for WordPress, BuddyPress and bbPress plugin contained an arbitrary file upload vulnerability in the rtmedia_api_process_rtmedia_upload_media_request() function through version 4.6.15, caused by inadequate file type validation. Any authenticated user with at least subscriber privileges could upload unrestricted file types to the server, potentially enabling remote code execution. The vulnerability was fixed in version 4.6.16.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings