The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media items associated with draft or private posts.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bbpress
Bbpress bbpress Buddypress Buddypress buddypress Rtcamp Rtcamp rtmedia Wordpress Wordpress wordpress |
|
| Vendors & Products |
Bbpress
Bbpress bbpress Buddypress Buddypress buddypress Rtcamp Rtcamp rtmedia Wordpress Wordpress wordpress |
Sat, 13 Dec 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media items associated with draft or private posts. | |
| Title | rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-15T15:47:54.693Z
Reserved: 2025-08-19T23:21:42.590Z
Link: CVE-2025-9218
Updated: 2025-12-15T15:43:30.570Z
Status : Received
Published: 2025-12-13T16:16:57.000
Modified: 2025-12-13T16:16:57.000
Link: CVE-2025-9218
No data.
OpenCVE Enrichment
Updated: 2025-12-14T21:15:10Z