SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-66592

CRITICAL · CVSS 9.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects rtMedia for WordPress, BuddyPress, and bbPress versions up to 4.7.11, allowing unauthenticated attackers to execute SQL injection attacks. This could lead to unauthorized access to sensitive data or complete database compromise. WordPress site administrators using these versions should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-66592
Severity
CRITICAL
CVSS
9.3
EPSS
0.29%
WordPress

Original NVD Description

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.