WordPress security changelog
MEDIUM CVE-2026-74010 Deferred

bbPress permits unauthenticated unauthorized state changes

bbPress through 2.6.14 does not enforce the required authorization on an affected operation. An unauthenticated remote request can cross that access-control boundary and alter protected state.

CVE / CNA score 5.3 CVSS 3.1 · audit@patchstack.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
bbPress
Plugin slug
bbpress
Affected
n/a through 2.6.14
Safe version
See mitigation notes
Published
Aug 31, 2026
Weakness
CWE-862 — Missing Authorization

This CVE was published Aug 31, 2026 and is one of 5 known issues for this plugin.

Update, patch or deactivate.

No fixed release is identified. Update when a confirmed patch becomes available; until then, restrict or disable the affected bbPress functionality when warranted and review unexpected forum or configuration changes.

No confirmed safe version is listed. Consider a vendor-supported patch or temporarily restricting the affected functionality while you assess the risk.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Primary and upstream sources