Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-88912

Опубликовано: 13 сент. 2026
Источник: nvd
CVSS3: 4.2
EPSS Низкий

Описание

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.

EPSS

Процентиль: 2%
0.00119
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 4.2
github
10 дней назад

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.

EPSS

Процентиль: 2%
0.00119
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-639