
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40773 is a Broken Access Control vulnerability (subscriber-level) in the rtMedia for WordPress, BuddyPress and bbPress plugin, affecting all versions up to and including 4.7.9. The flaw allows authenticated users with low privileges (e.g., subscribers) to perform unauthorized actions beyond their intended permissions. It was published on June 15, 2026, and assigned by Patchstack. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before executing sensitive operations. An attacker with a low-privilege WordPress account (subscriber role) can send crafted network requests to trigger restricted functionality — such as modifying media data or user-related settings — without proper authorization checks. The attack requires network access and a valid low-privilege account, but no user interaction or elevated privileges beyond that (Patchstack).
Successful exploitation allows authenticated low-privilege users to modify data and permissions they should not have access to, resulting in a high integrity impact with no confidentiality or availability impact. Attackers could alter subscriber data, manipulate media entries, or potentially modify user roles across WordPress, BuddyPress, and bbPress installations. This could facilitate unauthorized content manipulation or privilege escalation within the affected site (Patchstack).
admin-ajax.php action) with the subscriber session cookie, targeting a restricted operation such as editing or deleting media entries or modifying user data.wp-admin/admin-ajax.php with rtMedia-specific action parameters outside normal usage patterns.The vendor (rtCamp Inc.) has released a patched version of the plugin; users should update rtMedia for WordPress, BuddyPress and bbPress to version 4.7.10 or later immediately. As a temporary workaround, site administrators can restrict user registration or disable the plugin until the update is applied. Limiting subscriber-level account creation and monitoring for unusual activity on plugin endpoints is also advisable (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."