← WordPress Vulnerabilities
WordPress security by component

bbpress

bbpress adds forum and discussion board functionality to WordPress.

bbpress (bbpress) is a WordPress plugin with 5 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.

Plugin slug: bbpress

CVE-2026-62137: bbPress exposes sensitive data without authentication

bbPress through 2.6.14 lacks authorization on a data-retrieval path reachable without authentication. The CNA vector requires no user interaction and rates confidentiality impact as low. The authoritative export does not identify the endpoint, action, parameter, protected object, or sensitive fields returned.

PublishedSep 11, 2026
Known safe version2.6.15
Published vulnerabilities for bbpress
Safe version
Sep 11, 2026 CVE-2026-62137
bbPress exposes sensitive data without authentication
bbPress through 2.6.14 lacks authorization on a data-retrieval path reachable without authentication. The CNA vector requires no user interaction and rates confidentiality impact as low. The authoritative export does not identify the endpoint, action, parameter, protected object, or sensitive fields returned.
2.6.15
CVE5.3
NVDPending
Aug 31, 2026 CVE-2026-74010
bbPress permits unauthenticated unauthorized state changes
bbPress through 2.6.14 does not enforce the required authorization on an affected operation. An unauthenticated remote request can cross that access-control boundary and alter protected state.
See mitigation notes
CVE5.3
NVDPending
Mar 05, 2025 CVE-2025-1435
bbPress: Cross-site request forgery
bbPress is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.3
NVDPending
May 29, 2020 CVE-2020-13693
Bbpress: A security weakness
Bbpress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD9.8
May 26, 2020 CVE-2020-13487
Bbpress: Cross-site scripting
Bbpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8