bbPress
bbPress has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 7 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 2 high. 2020 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (43%). Other recurring categories include Cross-Site Request Forgery (CSRF), Improper Privilege Management.
Every one of the 7 issues recorded for bbPress has a vendor fix available, so running the current release closes all known holes.
7 independent researchers contributed these findings, one record each. bbPress is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2020-13693bbPress <= 2.6.4 - Unauthenticated Privilege Escalation
Read the full analysisVulnerability Records

bbPress
Author
John James Jacoby
Are you looking for a timeless, elegant, and streamlined discussion board? bbPress is easy to integrate, easy to use, and is built to scale with your growing community. bbPress is intentionally simple yet infinitely powerful forum software, built by contributors to WordPress.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C