rtMedia for WordPress, BuddyPress and bbPress - XML injection (XXE)
Severity pending
Summary
Full name
rtMedia for WordPress, BuddyPress and bbPress 4.6.2 - XML injection (XXE)
Code name
State
Private
Release date
Dec 6, 2024
Affected product
rtMedia for WordPress, BuddyPress and bbPress
Affected version(s)
Version 4.6.2
Vulnerability name
XML injection (XXE)
Vulnerability type
Remotely exploitable
No
CVSS v4.0 vector string
CVSS:4.0/AV:N/AT:N/AC:L/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U
Exploit available
No
CVE ID(s)
Description
rtMedia for WordPress, BuddyPress and bbPress 4.6.2 was found to be vulnerable. Access to external entities in XML parsing is enabled in myapp/lib/getid3/getid3.lib.php.
Vulnerability
Skims by Fluid Attacks discovered a XML injection (XXE) in rtMedia for WordPress, BuddyPress and bbPress 4.6.2. The following is the output of the tool:
Skims output
Our security policy
We have reserved the ID CVE-2025-22625 to refer to this issue from now on.
System Information
Version: rtMedia for WordPress, BuddyPress and bbPress 4.6.2
Mitigation
There is currently no patch available for this vulnerability.
Timeline
Vulnerability discovered
Dec 6, 2024
Public disclosure
Jan 7, 2025