Executive brief
bbPress is a popular WordPress plugin that enables discussion forums and community features on WordPress sites. A vulnerability allows unauthenticated attackers to access sensitive data such as passwords, emails, or payment details, potentially compromising user privacy and enabling account takeover or fraud.
Technical details
bbPress versions 2.6.14 and earlier are vulnerable to unauthenticated sensitive data exposure, a vulnerability that allows attackers to bypass authentication controls and access private user information. The exact attack vector and vulnerable component are not detailed in the advisory, but the attack requires no authentication and is likely exploitable via network access. Attackers can retrieve and steal sensitive information including passwords, email addresses, and payment details. A patch is available in version 2.6.15 and later.
Affected products
- bbPress bbPress <=2.6.14
Timeline
- 2026-08-25: disclosed: Reported by Ananda Dhakal to Patchstack
- 2026-09-11: advisory: Published by Patchstack
- 2026-09-11: patched: Version 2.6.15 available