CVE-2026-89301
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to ins
Summary
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the process function in all versions up to, and including, 4.7.13 This makes it possible for unauthenticated attackers to delete arbitrary safe files on the server.. The public nonce (rtmedia_upload_nonce) is emitted into frontend JavaScript on any page rendering the rtMedia gallery or upload shortcode, making it retrievable by unauthenticated visitors without any prior authentication or privileged action.
Published 2026-10-10 · first seen here 2026-10-10
Analysis & write-ups
No technical write-up from a research team yet. Contact Zero checks Unit 42, Google/Mandiant, Microsoft, Talos, CrowdStrike, Rapid7, watchTowr and others several times a day, plus NVD and CISA reference links.
Where it shows in your logs
Server or web application · Authentication bypass or missing authorisation medium confidence
What to look for
- Admin or API actions with no successful login before them in the same session
- New admin accounts, API keys or tokens created shortly after unusual requests
- Requests to admin or API endpoints from internet IPs
- The application's process (w3wp.exe, java, tomcat, node, php-fpm, httpd, python) starting shells or LOLBins (cmd, powershell, sh, bash, curl, wget, certutil)
- New script files in web roots (.jsp, .aspx, .php): a web shell
- Requests to unusual URLs on the application from internet IPs right before any of the above
- Outbound connections from the server to new external IPs
Data sources
Web server and WAF logs · ATT&CK DS0015 Application Log Content
- Sentinel
W3CIISLogAppServiceHTTPLogsAzureDiagnostics (Application Gateway / Front Door WAF)_Im_WebSession- Splunk
Web.Webms:iis:autoaccess_combinedWAF / proxy sourcetypes- CrowdStrike
Falcon Next-Gen SIEM: third-party web / WAF / proxy logs
Process creation · ATT&CK DS0009 Process Creation
- Sentinel
DeviceProcessEventsSecurityEvent (4688)Sysmon Event ID 1_Im_ProcessCreate- Splunk
Endpoint.ProcessesXmlWinEventLog:Microsoft-Windows-Sysmon/OperationalWinEventLog:Security (4688)- CrowdStrike
ProcessRollup2SyntheticProcessRollup2
File creation · ATT&CK DS0022 File Creation
- Sentinel
DeviceFileEventsSysmon Event ID 11_Im_FileEvent- Splunk
Endpoint.FilesystemSysmon Event ID 11- CrowdStrike
NewExecutableWrittenNewScriptWritten*FileWritten events
Network connections · ATT&CK DS0029 Network Connection Creation / Network Traffic Flow
- Sentinel
DeviceNetworkEventsCommonSecurityLog (firewall)_Im_NetworkSession- Splunk
Network_Traffic.All_TrafficFirewall sourcetypes (pan:traffic, fortigate_traffic, cisco:asa)- CrowdStrike
NetworkConnectIP4NetworkReceiveAcceptIP4NetworkConnectIP6
Authentication and sessions · ATT&CK DS0028 Logon Session Creation / DS0002 User Account Authentication
- Sentinel
SigninLogsSecurityEvent (4624, 4625, 4648)DeviceLogonEventsIdentityLogonEvents_Im_Authentication- Splunk
Authentication.Authenticationpan:globalprotectVPN sourcetypes- CrowdStrike
UserLogonUserLogonFailed2Falcon Identity Protection events
Account and group changes · ATT&CK DS0002 User Account Creation / Modification
- Sentinel
SecurityEvent (4720, 4728, 4732, 4756)AuditLogsIdentityDirectoryEvents- Splunk
Change.All_Changes (Account_Management)WinEventLog:Security (4720, 4732)- CrowdStrike
UserAccountCreatedUserAccountAddedToGroup
A generic baseline worked out from the product type and weakness (CWE-862), not a detection. Check table and field names against your environment. Hunt queries for Sigma, Splunk, Sentinel and CrowdStrike are coming.
References
- NVD entry
- https://github.com/rtCamp/rtMedia/releases/tag/4.7.14
- https://plugins.trac.wordpress.org/browser/buddypress-media/tags/4.7.13/app/main/controllers/shortcodes/RTMediaGalleryShortcode.php#L151
- https://plugins.trac.wordpress.org/browser/buddypress-media/tags/4.7.13/app/main/controllers/upload/RTMediaUploadEndpoint.php#L85
- https://plugins.trac.wordpress.org/browser/buddypress-media/tags/4.7.13/app/main/controllers/upload/RTMediaUploadModel.php#L49
- https://plugins.trac.wordpress.org/browser/buddypress-media/tags/4.7.13/app/main/controllers/upload/processors/RTMediaUploadFile.php#L180
- https://plugins.trac.wordpress.org/browser/buddypress-media/tags/4.7.13/app/main/controllers/upload/processors/RTMediaUploadFile.php#L253
- https://plugins.trac.wordpress.org/browser/buddypress-media/tags/4.7.13/app/main/controllers/upload/processors/RTMediaUploadFile.php#L91
- https://plugins.trac.wordpress.org/browser/buddypress-media/tags/4.7.13/app/main/routers/RTMediaRouter.php#L120
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ea679227-5ab3-408b-ae1b-340099880789?source=cve