PLUGIN SECURITY
Is Buddypress Media safe?
Add albums, photo, audio/video upload, privacy, sharing, front-end uploads & more. All this works on mobile/tablets devices.
What this plugin does
- Slug:
buddypress-media - Author: rtCamp
- 7000+ active installs
- 74/100 rating (152 reviews on wordpress.org)
- 1357885 all-time downloads
- On WordPress.org since 2012-08-06
albumaudiobuddypressmediamultimedia
Maintenance status
- Latest known version: 4.7.11
- Last updated: 2026-08-18 6:37am GMT
- Tested up to WordPress: 7.0.4
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
11 known CVEs on file for Buddypress Media.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-66592 | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.7.12 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.3 | < 4.7.12 | 4.7.12 | 2026-08-20 | ⚠ update needed |
| CVE-2026-40773 | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.7.10 | Missing Authorization | Medium 6.5 | < 4.7.10 | 4.7.10 | 2026-04-21 | ✓ fixed in latest |
| CVE-2026-25325 | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.7.9 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | Medium 5.3 | < 4.7.9 | 4.7.9 | 2026-02-01 | ✓ fixed in latest |
| CVE-2026-15287 | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.19 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 4.6.19 | 4.6.19 | 2024-04-29 | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.19 | — | Unknown | < 4.6.19 | 4.6.19 | 2024-04-29 | ✓ fixed in latest |
| CVE-2024-3293 | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.19 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 4.6.19 | 4.6.19 | 2024-04-22 | ✓ fixed in latest |
| CVE-2023-5931 | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.16 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 4.6.16 | 4.6.16 | 2023-11-29 | ✓ fixed in latest |
| CVE-2023-5939 | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.16 | Improper Control of Generation of Code ('Code Injection') | High 7.2 | < 4.6.16 | 4.6.16 | 2023-11-29 | ✓ fixed in latest |
+ 22 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-41951 | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.15 | Missing Authorization | Medium 4.3 | < 4.6.15 | 4.6.15 | 2023-09-06 | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.15 | — | Unknown | < 4.6.15 | 4.6.15 | 2023-09-04 | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.15 | — | Unknown | < 4.6.15 | 4.6.15 | 2023-09-04 | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.2.1 | — | Unknown | < 4.2.1 | 4.2.1 | 2016-12-21 | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 3.10.2 | — | Unknown | < 3.10.2 | 3.10.2 | 2016-01-28 | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 3.7.40 | — | Unknown | < 3.7.40 | 3.7.40 | 2015-04-28 | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 3.7.19 | — | Unknown | < 3.7.19 | 3.7.19 | 2014-11-24 | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.7.4 | — | Low 3.7 | < 4.7.4 | 4.7.4 | 0000-00-00 | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.7.11 | — | Unknown | < 4.7.11 | 4.7.11 | 0000-00-00 | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.2.1 | — | Unknown | < 4.2.1 | 4.2.1 | — | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 3.10.2 | — | Unknown | < 3.10.2 | 3.10.2 | — | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.15 | — | Unknown | < 4.6.15 | 4.6.15 | — | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.15 | — | Unknown | < 4.6.15 | 4.6.15 | — | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress & bbPress 3.7.39 - SQL Injection | — | Unknown | < 3.7.40 | 3.7.40 | — | ✓ fixed in latest |
| — | trMedia for WordPress <= 3.10.1 - XSS | — | Unknown | < 3.10.2 | 3.10.2 | — | ✓ fixed in latest |
| — | trMedia for WordPress <= 4.2 - Unspecified Issues | — | Unknown | < 4.2.1 | 4.2.1 | — | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress < 4.6.15 - Missing Authorization to Settings Update | — | Unknown | < 4.6.15 | 4.6.15 | — | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress < 4.6.15 - Missing Authorization to Sensitive Information Exposure | — | Unknown | < 4.6.15 | 4.6.15 | — | ✓ fixed in latest |
| — | rtMedia for WordPress, BuddyPress and bbPress < 4.6.19 - Subscriber+ SQL Injection | — | Unknown | < 4.6.19 | 4.6.19 | — | ✓ fixed in latest |
| CVE-2025-9218 | rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function | — | Unknown | < 4.7.4 | 4.7.4 | — | ✓ fixed in latest |
| CVE-2026-59551 | rtMedia for WordPress, BuddyPress and bbPress < 4.7.11 - Authenticated (Subscriber+) SQL Injection | — | Unknown | < 4.7.11 | 4.7.11 | — | ✓ fixed in latest |
| CVE-2026-59549 | rtMedia for WordPress, BuddyPress and bbPress < 4.7.11 - Unauthenticated SQL Injection | — | Unknown | < 4.7.11 | 4.7.11 | — | ✓ fixed in latest |
How to fix it
Keep Buddypress Media updated — 4.7.11 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Presto Player — 100000+ active installs — 96/100 (339) — max PHP <8.0
- Seriously Simple Podcasting — 30000+ active installs — 94/100 (329) — max PHP 8.4
- Compact WP Audio Player — 20000+ active installs — 82/100 (69) — max PHP 8.4
- AudioIgniter Music Player — 10000+ active installs — 92/100 (64) — max PHP 8.4
- HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player — 10000+ active installs — 92/100 (167) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.