What is CVE-2026-59551?
CVE-2026-59551 is a Subscriber-level SQL Injection vulnerability found in rtMedia plugin versions 4.7.10 and below for WordPress, BuddyPress, and bbPress. It allows authenticated users with 'Subscriber' role to inject SQL queries into the database. To mitigate this, it is recommended to update the rtMedia plugin to the latest version.
Azərbaycanca: CVE-2026-59551, rtMedia plagininin 4.7.10 və aşağı versiyalarında mövcud olan Subscriber səviyyəli SQL Injection zəifliyidir. Bu zəiflik WordPress, BuddyPress və bbPress platformalarında "Subscriber" rolu ilə autentifikasiya olunmuş istifadəçilərə verilənlər bazasına SQL sorğuları yeritməyə imkan verir. Zəifliyi aradan qaldırmaq üçün rtMedia plaginini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What role level of users can exploit the CVE-2026-59551 vulnerability?
This vulnerability can be exploited by authenticated users with the 'Subscriber' role.
What should be done to mitigate the CVE-2026-59551 SQL Injection vulnerability?
It is recommended to update the rtMedia plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.