CVE-2026-88912
EUVD-2026-7695713.09.2026, 06:16
The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.