Impact
The vulnerability in bbPress versions up to 2.6.14 arises from a missing authorization check that allows non‑privileged users to bypass the plugin's access control logic, granting them the ability to view or alter protected forum content. This improper authorization flaw is classified as CWE‑862 and can be exploited from a web browser or automated script.
Affected Systems
Affected systems include WordPress sites that have John James Jacoby's bbPress plugin installed in any release from the first version up through 2.6.14. The vulnerability is present in all builds prior to 2.6.15, meaning any site that has not upgraded beyond that version is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, but the EPSS score is not available, and the vulnerability has not appeared in CISA's KEV catalog, implying limited exposure so far. Attackers would need to craft a request to a vulnerable bbPress endpoint; no public exploit code is documented, yet the improper authorization logic could enable further privilege escalation if the attacker can modify configuration or add posts. Administrators should treat this as a risk worth addressing promptly, especially if the site hosts confidential or high‑value discussions.
OpenCVE Enrichment