CVE-2025-9218EPSS p23.1%
CVE-2025-9218CVE-2025-9218
Description
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media items associated with draft or private posts.
Scoring
| CVSS | 3.7 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.32% probability of exploitation · percentile 23.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |