WordPress security by component
bbpress
Plugin description
bbpress adds forum and discussion board functionality to WordPress.
bbpress (bbpress) is a WordPress plugin with 5 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
bbpressLatest vulnerability
CVE-2026-62137: bbPress exposes sensitive data without authentication
bbPress through 2.6.14 lacks authorization on a data-retrieval path reachable without authentication. The CNA vector requires no user interaction and rates confidentiality impact as low. The authoritative export does not identify the endpoint, action, parameter, protected object, or sensitive fields returned.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62137
bbPress exposes sensitive data without authentication
bbPress through 2.6.14 lacks authorization on a data-retrieval path reachable without authentication. The CNA vector requires no user interaction and rates confidentiality impact as low. The authoritative export does not identify the endpoint, action, parameter, protected object, or sensitive fields returned.
|
2.6.15 |
CVE5.3
NVDPending
|
| Aug 31, 2026 |
CVE-2026-74010
bbPress permits unauthenticated unauthorized state changes
bbPress through 2.6.14 does not enforce the required authorization on an affected operation. An unauthenticated remote request can cross that access-control boundary and alter protected state.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Mar 05, 2025 |
CVE-2025-1435
bbPress: Cross-site request forgery
bbPress is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.3
NVDPending
|
| May 29, 2020 |
CVE-2020-13693
Bbpress: A security weakness
Bbpress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD9.8
|
| May 26, 2020 |
CVE-2020-13487
Bbpress: Cross-site scripting
Bbpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|