PatchSiren

rtCamp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH rtCamp CVE published 2026-07-27

CVE-2026-59551

The CVE-2026-59551 vulnerability is a SQL injection issue in rtMedia for WordPress, BuddyPress, and bbPress plugin versions <= 4.7.10. This vulnerability allows a subscriber to inject malicious SQL, potentially leading to data breaches or system compromise. Users of affected versions should review and apply patches or mitigations provided by the vendor. The CVE record was published on 2026-07-27T15:17:05. [truncated]

CRITICAL rtCamp CVE published 2026-07-27

CVE-2026-59549

CVE-2026-59549 is a critical vulnerability in rtMedia for WordPress, BuddyPress and bbPress versions up to 4.7.10. The vulnerability allows unauthenticated SQL injection, with a CVSS score of 9.3. This class of vulnerability typically allows attackers to inject malicious SQL code, potentially leading to data breaches or system compromise. Administrators should prioritize patching this vulnerability. The C [truncated]

MEDIUM rtcamp CVE published 2026-07-10

CVE-2026-15287

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all versions up to, and including, 4.6.18. This vulnerability allows authenticated attackers, with subscriber access and above, to append additional SQL queries into existing queries, potentially leading to sensitive information extraction from the database.