Impact
An unauthenticated vulnerability in the WordPress bbPress plugin versions 2.6.14 and earlier allows an attacker to read sensitive data that should be restricted to privileged users. The weakness lies in inadequate authorization thereby enabling disclosure of potentially confidential information such as configuration settings.
Affected Systems
Any WordPress site using the bbPress plugin version 2.6.14 or prior is affected. The vulnerability impacts the bbPress implementation distributed by John James Jacoby. Sites that have not upgraded to at least version 2.6.15 remain vulnerable.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate impact assessment. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The CISA KEV catalog lists it as not a known exploited vulnerability in the wild. Based on the description, it is inferred that attackers could exploit the flaw by sending unauthenticated HTTP requests to bbPress endpoints that expose sensitive data. This attack vector relies on the lack of authorization checks.
OpenCVE Enrichment