CVE-2026-105892: Patch for rtMedia closes path traversal
This text was generated using artificial intelligence (AI).CVE-2026-105892 affects rtMedia for WordPress, BuddyPress, and bbPress from rtCamp. The vulnerability is described as a Path Traversal and affects versions up to and including 4.7.13. For version 4.7.14 a fix release is available.
The vulnerability affects the WordPress plugin with the package name buddypress-media. The error class Path Traversal describes insufficient limitation of file paths to designated directories.
For CVE-2026-105892, a CVSS score of 9.8 is documented according to Patchstack. The corresponding CVSS vector describes a network attack with low complexity, no authentication required, and no user interaction. The issue includes Path Traversal and the ability to read and delete files outside of intended directories as well as impacting their availability (Confidentiality: High, Integrity: High, Availability: High).
The provided fix was released according to the rtCamp advisory on October 6, 2026. The CVE was documented on October 10, 2026 . For prioritization, the plugin version used on individual WordPress instances is therefore relevant.
Measures for Affected WordPress Installations
The primary measure is to update rtMedia to version 4.7.14 or higher. The review should encompass the individual installations where the plugin is used.
Recommended steps:
Identify WordPress systems with rtMedia and check the plugin version in use.
Prioritize installations up to and including version 4.7.13.
Update rtMedia to version 4.7.14 or higher.
Check file upload directories for unexpected files.
Document the patch status for each installation in a traceable manner.
Establish continuous vulnerability and vendor risk monitoring.
Visibility of publicly accessible installations
In WordPress installations, rtMedia can be visible through externally identifiable plugin file paths or references in the HTML source code. These signals assist in determining which publicly accessible systems should be checked for an affected component.
The specific vulnerable version cannot be determined solely from external detection. It must be technically verified on the respective WordPress installation. Additionally, updating to the provided fix remains the responsibility of the system operations team.
WordPress is widely used in the DACH region—by companies, authorities, and non-profit organizations alike. Operators using WordPress instances with rtMedia should document the patch status and check legal notification obligations in case of signs of a compromise involving personal data processing: In Germany and Austria, the GDPR notification obligation applies under Art. 33 GDPR (72-hour deadline to the relevant supervisory authority); in Switzerland, the notification obligation under the revised ISG applies to the BACS.
Check externally visible components
LocateRisk supports External Attack Surface Management by making publicly accessible systems and externally recognizable software visible. This allows WordPress instances with rtMedia signals in your own infrastructure to be specifically included in the review of CVE-2026-105892.
Continuous Vendor Risk Management can be used to monitor security alerts from relevant manufacturers and dependencies. This allows for early detection and prioritized handling of new vulnerability reports for deployed WordPress plugins—regardless of whether affected installations are already recorded in the internal asset inventory or only become visible through active monitoring.
Am I affected?
This affects rtMedia for WordPress in the versions mentioned above; the vulnerability was fixed in 4.7.14. Anyone wanting to know whether rtMedia for WordPress is visible in their own publicly accessible infrastructure can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-105892 refers to a path traversal vulnerability in the WordPress plugin rtMedia for WordPress, BuddyPress and bbPress (package name: buddypress-media) by rtCamp, according to Patchstack. It allows attackers to access file paths outside intended directories without prior authentication and read, delete, or disrupt the availability of files.
This affects all versions of the plugin up to and including 4.7.13. Version 4.7.14 fixes the vulnerability. The patch is available through the official rtCamp GitHub repository.
At the time of the publication of this notice on October 10, 2026, there is no evidence of active exploitation according to available sources. The update to version 4.7.14 should still be applied promptly.
As of: October 10, 2026. This article is for general informational purposes and does not constitute legal, security, or action advice in individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee the accuracy, correctness, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-105892
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.