Extension WordPress
Vulnérabilités bbPress
Cette page rassemble les failles publiées pour bbPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de bbPress
6 fiches
bbPress <= 2.6.11 – Cross-Site Request Forgery to Limited Privilege Escalation
The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.11. This is due to missing or incorrect nonce validation on the bbp_user_add_role_on_register() function. This makes it possible for unauthenticated…
*-2.6.11
2.6.12
04/03/2025
bbPress <= 2.6.4 – Authenticated (Admin+) Stored Cross-Site Scripting via the forums list table
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.
*-2.6.4
2.6.5
28/05/2020
bbPress <= 2.6.4 – Unauthenticated Privilege Escalation
The bbPress plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to, and including, 2.6.4. This is due to a logic bug within the signup process. This makes it possible for unauthenticated attackers to grant…
*-2.6.4
2.6.5
28/05/2020
bbPress < 2.5.13 – Unauthenticated Blind SQL Injection
The bbPress plugin for WordPress is vulnerable to blind SQL Injection via the ‘anonymous_data’ parameter in versions up to, and including, 2.5.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
[*, 2.5.13)
2.5.13
13/11/2017
bbPress <= 2.5.9 – Cross-Site Scripting
The bbPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping on user profile fields. This makes it possible for unauthorized attackers to inject…
*-2.5.9
2.5.10
13/07/2016
bbPress < 2.5.9 – Stored Cross-Site Scripting
The bbPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bbp_mention_filter function in versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject…
[*, 2.5.9)
2.5.9
03/05/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.