CVE-2026-59549: Critical SQL injection in the WordPress plugin rtMedia


This text was generated using artificial intelligence (AI).On July 27, 2026, a critical vulnerability was discovered in the WordPress plugin rtMedia for WordPress, BuddyPress, and bbPress published. The vulnerability, registered as CVE-2026-59549, according to the security platform Patchstack with a CVSS score of 9.3 vulnerability. It allows for SQL injection, which can be exploited by attackers without prior authentication, and poses a high risk to all websites using an affected version of the plugin.

Are my systems affected? Check now →