CVE-2025-9218

T

he rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media items associated with draft or private posts.

Configurations

No configuration.

History

15 Dec 2025, 18:22

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-13 16:16

Updated : 2025-12-15 18:22


NVD link : CVE-2025-9218

Mitre link : CVE-2025-9218

CVE.ORG link : CVE-2025-9218


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization