The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.
We have discovered 523 live websites that are affected by CVE-2023-5939.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 523 live websites (37% of Buddypress Media install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 53 versions ( 76% of all versions) |
| 208 websites | |
| 48 websites | |
| 37 websites | |
| 30 websites | |
| 25 websites | |
| 20 websites | |
| 13 websites | |
| 13 websites | |
| 12 websites | |
| 9 websites |
| .com | 227 websites |
| .org | 60 websites |
| .ru | 21 websites |
| .de | 20 websites |
| .fr | 18 websites |
| .it | 18 websites |
| .net | 13 websites |
| .eu | 8 websites |
| .es | 8 websites |
| .ca | 6 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.do | ***,*** | ||
| *********************.org | ***,*** | ||
| **********.ru | *,***,*** | ||
| ******.com | *,***,*** | ||
| *****.org | *,***,*** | ||
| **************.it | *,***,*** | ||
| ****************.org | *,***,*** | ||
| ******.com | *,***,*** | ||
| **********.com | *,***,*** | ||
| *******************.club | *,***,*** |
FAQ