CVE Database /
CVE-2023-5939
CVE · High
CVE-2023-5939 — rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.16
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-5939
|
rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.16 |
Improper Control of Generation of Code ('Code Injection') |
High
7.2
|
< 4.6.16
|
4.6.16 |
2023-11-29 |
—
|
CVE-2023-5939
The rtMedia for WordPress, BuddyPress and bbPress plugin contains an arbitrary file upload vulnerability in its Import rtMedia Settings feature affecting versions through 4.6.15. The plugin fails to properly validate file types during the import process, allowing administrators and higher-privileged users to upload any file type to the server. This vulnerability could enable remote code execution by uploading malicious files that compromise the affected website.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings