PT-2025-51084 · Unknown+3 · Buddypress+3

Kenneth Dunn

·

Published

2025-12-13

·

Updated

2025-12-13

·

CVE-2025-9218

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions rtMedia for WordPress, BuddyPress and bbPress versions 4.7.0 through 4.7.3
Description The rtMedia plugin for WordPress, BuddyPress, and bbPress has an information disclosure issue. Missing authorization within the handle rest pre dispatch() function, specifically when the Godam plugin is active, allows unauthenticated attackers to access media items linked to draft or private posts.
Recommendations Update to version 4.7.4 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-9218

Affected Products

Buddypress
Godam
Bbpress
Rtmedia