Description
Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects bbPress: from n/a through 2.6.14.
Published: 2026-08-31
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in bbPress versions up to 2.6.14 arises from a missing authorization check that allows non‑privileged users to bypass the plugin's access control logic, granting them the ability to view or alter protected forum content. This improper authorization flaw is classified as CWE‑862 and can be exploited from a web browser or automated script.

Affected Systems

Affected systems include WordPress sites that have John James Jacoby's bbPress plugin installed in any release from the first version up through 2.6.14. The vulnerability is present in all builds prior to 2.6.15, meaning any site that has not upgraded beyond that version is susceptible.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, but the EPSS score is not available, and the vulnerability has not appeared in CISA's KEV catalog, implying limited exposure so far. Attackers would need to craft a request to a vulnerable bbPress endpoint; no public exploit code is documented, yet the improper authorization logic could enable further privilege escalation if the attacker can modify configuration or add posts. Administrators should treat this as a risk worth addressing promptly, especially if the site hosts confidential or high‑value discussions.

Generated by OpenCVE AI on August 31, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade bbPress to 2.6.15 or a later release from the vendor's official source.
  • If an upgrade is not possible, restrict the plugin's use to authenticated administrators by disabling frontend access or configuring role‑based visibility settings.
  • Audit any custom code or dependent plugins that adjust bbPress post visibility to ensure they do not reintroduce the missing authorization check.

Generated by OpenCVE AI on August 31, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14.
Title WordPress bbPress plugin <= 2.6.14 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T12:07:43.112Z

Reserved: 2026-08-14T10:16:11.319Z

Link: CVE-2026-74010

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T13:18:25.243

Modified: 2026-08-31T13:18:25.243

Link: CVE-2026-74010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T13:30:04Z

Weaknesses