CVE-2025-9218
Last modified
CVE-2025-9218 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media items associated with draft or private posts.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media items associated with draft or private posts.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-9218?
How severe is CVE-2025-9218?
How do I fix CVE-2025-9218?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-9212The WP Dispatcher plugin for WordPress is vulnerable to arbi…7.5
- CVE-2025-9213The TextBuilder plugin for WordPress is vulnerable to Cross-…8.8
- CVE-2025-9214A missing authentication vulnerability was reported in some …5.4
- CVE-2025-9215The StoreEngine – Powerful WordPress eCommerce Plugin for Pa…6.5
- CVE-2025-9216The StoreEngine – Powerful WordPress eCommerce Plugin for Pa…8.8
- CVE-2025-9217The Slider Revolution plugin for WordPress is vulnerable to …6.5
- CVE-2025-9219The Post SMTP – WP SMTP Plugin with Email Logs and Mobile Ap…4.3
- CVE-2025-9222GitLab has remediated an issue in GitLab CE/EE affecting all…5.4
- CVE-2025-9223Zohocorp ManageEngine Applications Manager versions 178100 a…8.8
- CVE-2025-9225Stored cross-site scripting (XSS) in the web interface of Mi…5.5
- CVE-2025-9226Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUti…4.6
- CVE-2025-9227Zohocorp ManageEngine OpManager versions 128609 and below ar…6.5
Are you affected by CVE-2025-9218?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
