Executive brief
bbPress is a popular WordPress plugin that adds forum and discussion features to WordPress sites. A broken access control vulnerability allows unauthenticated users to access pages or perform actions they should not be permitted, potentially exposing private forum content or allowing unauthorized modifications. The vulnerability affects versions up to 2.6.14 and is fixed in version 2.6.15.
Technical details
This is a broken access control vulnerability (CWE-639) in bbPress that stems from incorrectly configured access control security levels. The flaw allows unauthenticated users to bypass permission checks and access pages or perform actions they should not be authorized for. Attack requires no authentication or special preconditions—any user can access the affected resource over the network. An attacker can view private forum content or perform unauthorized actions on forum data. The vulnerability is patched in version 2.6.15 and later.
Affected products
- John James Jacoby bbPress through 2.6.14
Timeline
- 2026-08-31: disclosed
- 2026-08-31: patched: Fixed in version 2.6.15