CVE-2026-40773
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-40773 is a Broken Access Control vulnerability (subscriber-level) in the rtMedia for WordPress, BuddyPress and bbPress plugin, affecting all versions up to and including 4.7.9. The flaw allows authenticated users with low privileges (e.g., subscribers) to perform unauthorized actions beyond their intended permissions. It was published on June 15, 2026, and assigned by Patchstack. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before executing sensitive operations. An attacker with a low-privilege WordPress account (subscriber role) can send crafted network requests to trigger restricted functionality — such as modifying media data or user-related settings — without proper authorization checks. The attack requires network access and a valid low-privilege account, but no user interaction or elevated privileges beyond that (Patchstack).

Impact

Successful exploitation allows authenticated low-privilege users to modify data and permissions they should not have access to, resulting in a high integrity impact with no confidentiality or availability impact. Attackers could alter subscriber data, manipulate media entries, or potentially modify user roles across WordPress, BuddyPress, and bbPress installations. This could facilitate unauthorized content manipulation or privilege escalation within the affected site (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the rtMedia for WordPress, BuddyPress and bbPress plugin (version ≤ 4.7.9) using tools like WPScan or by inspecting plugin directories.
  2. Obtain low-privilege account: Register or obtain a subscriber-level account on the target WordPress site (registration may be open or obtained via phishing).
  3. Identify vulnerable endpoints: Enumerate plugin-specific AJAX actions or REST API endpoints associated with rtMedia that lack proper capability checks.
  4. Craft unauthorized request: Send a crafted HTTP POST or GET request to the vulnerable endpoint (e.g., a WordPress admin-ajax.php action) with the subscriber session cookie, targeting a restricted operation such as editing or deleting media entries or modifying user data.
  5. Achieve unauthorized modification: The server processes the request without verifying the user's authorization level, allowing the attacker to successfully modify data or permissions beyond their intended access scope.

Indicators of compromise

  • Logs: WordPress access logs showing subscriber-level accounts making repeated POST requests to wp-admin/admin-ajax.php with rtMedia-specific action parameters outside normal usage patterns.
  • Logs: Unexpected modifications to media records, user metadata, or role assignments in the WordPress database coinciding with low-privilege user sessions.
  • Network: Unusual or high-frequency requests from a single subscriber account to plugin-related endpoints.
  • File System: Unexpected changes to media files or plugin-managed directories not initiated by administrators or editors.

Mitigation and workarounds

The vendor (rtCamp Inc.) has released a patched version of the plugin; users should update rtMedia for WordPress, BuddyPress and bbPress to version 4.7.10 or later immediately. As a temporary workaround, site administrators can restrict user registration or disable the plugin until the update is applied. Limiting subscriber-level account creation and monitoring for unusual activity on plugin endpoints is also advisable (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13147CRITICAL9.1
  • kirki
NoYesJul 20, 2026
CVE-2026-9833HIGH7.1
  • tag-groups
NoYesJul 20, 2026
CVE-2026-13432MEDIUM5.4
  • image-sizes
NoYesJul 20, 2026
CVE-2026-13156MEDIUM5.4
  • mailersend-official-smtp-integration
NoYesJul 20, 2026
CVE-2026-8825MEDIUM4.9
  • elementor
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management