[Go to site: main page, start]

Skip to:
Content
Pages
Categories
Search
Top
Bottom

bbPress <= 2.6.14 – Missing Authorization

  • @crzyhrse

    Participant

    bbPress <= 2.6.14 – Missing Authorization
    Wordfence Intelligence > Vulnerability Database > bbPress <= 2.6.14 – Missing Authorization
    5.3
    Missing Authorization
    CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
    CVE CVE-2026-74010
    CVSS 5.3 (Medium)
    Publicly Published August 31, 2026
    Last Updated September 1, 2026
    Researcher Ananda Dhakal
    Description
    The bbPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.6.14. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

    References
    vdp.patchstack.com

Viewing 13 replies - 1 through 13 (of 13 total)
  • @egsteam

    Participant

    I came to report this same thing.

    @stracy2

    Participant

    Is someone working a patch or fix?

    Wordfence gives alerts to this issue.

    patchstack, credited with finding this CVE:

    States “This security issue has a low severity impact and is unlikely to be exploited.” and has no vPatch. Here is that report.

    @robin-w

    Moderator

    I am not a bbpress author, just a moderator on the support forum.

    bbpress has been informed, and as you say patchstack says that the issue is

    Low priority
    No impactful threat
    This security issue has a low severity impact and is unlikely to be exploited.

    But of course it should be fixed.

    @egsteam

    Participant

    And that all made sense a year ago. However, with AI bots right now, we’re seeing them exploit all kinds of sites within 24 hours of a vulnerability being publicly announced to the public.

    What was acceptable a year ago no longer applies in this AI nightmare.

    @sculley

    Participant

    Most plugin authors fix these security issues within 24-48 hours after having received notice. I agree with @egsteam. There isn’t a security leak that is “low” enough priority to not look at. @robin-w, Can you please nudge the developers? Security issues should be on the top of the priority list no matter how “low.”

    @robin-w

    Moderator

    I have emailed the developers, but as I am not privy to the exact code at fault, I cannot give any reassurance as to exactly what the issue is.

    @sculley

    Participant

    Right. I was asking if you can follow up to nudge them to fix the security leak!

    @robin-w

    Moderator

    Just heard that it is fixed and due for release very shortly

    @sculley

    Participant

    Yay!!! Thank you so much!

    @crzyhrse

    Participant

    Yay also yay…!

    @johnjamesjacoby

    Keymaster

    Hey everyone,

    There isn’t a security leak that is “low” enough priority to not look at

    Totally agree, and I look at everything that comes in – it’s a lot right now 😂

    2.6.15 was just released with this fix, and a few others! 🎉

    @crzyhrse

    Participant

    @johnjamesjacoby & @robin-w

    Thank you for getting onto this so promptly…!!

    🙏🏽🌻🌈🇵🇸

    @egsteam

    Participant

    THANK YOU! We sure appreciate your timeliness!

Viewing 13 replies - 1 through 13 (of 13 total)
  • The topic ‘bbPress <= 2.6.14 – Missing Authorization’ is closed to new replies.
Skip to toolbar