SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59549

CRITICAL · CVSS 9.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

An unauthenticated SQL injection vulnerability exists in the rtMedia plugin for WordPress, affecting versions up to 4.7.10, allowing attackers to execute arbitrary SQL queries. This critical flaw can lead to unauthorized access to sensitive data and potential site compromise. WordPress site administrators using the affected plugin should prioritize immediate updates to mitigate the risk.

CVE
CVE-2026-59549
Severity
CRITICAL
CVSS
9.3
EPSS
0.23%
WordPress

Original NVD Description

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.