SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-88912

MEDIUM · CVSS 4.2

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The rtMedia plugin for WordPress prior to version 4.7.12 is vulnerable due to inadequate ownership checks, allowing users with subscriber-level access or higher to alter the privacy settings of other users' activities and media. This could lead to unauthorized exposure of private content or the concealment of public activities, posing a risk to user privacy. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential privacy breaches.

CVE
CVE-2026-88912
Severity
MEDIUM
CVSS
4.2
EPSS
N/A
WordPress

Original NVD Description

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.