bbPress <= 2.6.14 – Missing Authorization
-
bbPress <= 2.6.14 – Missing Authorization
Wordfence Intelligence > Vulnerability Database > bbPress <= 2.6.14 – Missing Authorization
5.3
Missing Authorization
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE CVE-2026-74010
CVSS 5.3 (Medium)
Publicly Published August 31, 2026
Last Updated September 1, 2026
Researcher Ananda Dhakal
Description
The bbPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.6.14. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.References
vdp.patchstack.com
- You must be logged in to reply to this topic.