CVE-2023-5931

CVE-2023-5931: rtMedia for WordPress, BuddyPress and bbPress < 4.6.16 - Subscriber+ RCE

Vendor Unknown
Product rtMedia for WordPress, BuddyPress and bbPress
Published December 26, 2023
Last update August 2, 2024

CVSS base score

—

What the vulnerability does

01Description

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server

Key dates

02Disclosure timeline

December 26, 2023 CVE published
August 2, 2024 Record updated