Junglewise Threat Intelligence

CVE-2026-62137: bbPress sensitive data exposure

CVE-2026-62137 · Severity: medium · CVSS 5.3 · Published 2026-09-11

Executive brief

bbPress is a popular WordPress plugin that enables discussion forums and community features on WordPress sites. A vulnerability allows unauthenticated attackers to access sensitive data such as passwords, emails, or payment details, potentially compromising user privacy and enabling account takeover or fraud.

Technical details

bbPress versions 2.6.14 and earlier are vulnerable to unauthenticated sensitive data exposure, a vulnerability that allows attackers to bypass authentication controls and access private user information. The exact attack vector and vulnerable component are not detailed in the advisory, but the attack requires no authentication and is likely exploitable via network access. Attackers can retrieve and steal sensitive information including passwords, email addresses, and payment details. A patch is available in version 2.6.15 and later.

Affected products

  • bbPress bbPress <=2.6.14

Timeline

  • 2026-08-25: disclosed: Reported by Ananda Dhakal to Patchstack
  • 2026-09-11: advisory: Published by Patchstack
  • 2026-09-11: patched: Version 2.6.15 available

References