bbPress

bbPress has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 7 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 2 high. 2020 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (43%). Other recurring categories include Cross-Site Request Forgery (CSRF), Improper Privilege Management.

Every one of the 7 issues recorded for bbPress has a vendor fix available, so running the current release closes all known holes.

7 independent researchers contributed these findings, one record each. bbPress is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage100%
Open

0

Fixed

7

Get automatic notifications for all bbPress vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2020-13693

bbPress <= 2.6.4 - Unauthenticated Privilege Escalation

Read the full analysis

Vulnerability Records

7 records
bbPress banner
Latestv2.6.15
3.9(342)
78/100
Last Updated
2026-09-03 (10d ago)
Active Installs
100,000+
Downloads
9,396,540
Requires WP
6.0+
Requires PHP
5.6.20+
Tested up to
WP 7.1
Created
2010-01-13 (17y ago)

Are you looking for a timeless, elegant, and streamlined discussion board? bbPress is easy to integrate, easy to use, and is built to scale with your growing community. bbPress is intentionally simple yet infinitely powerful forum software, built by contributors to WordPress.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C