GHSA-p9xp-xghp-gqvp
Dashboard / Vulnerabilities / GHSA-p9xp-xghp-gqvp
Summary: bbPress stored Cross-Site Scripting (XSS) vulnerability in the Forum creation section
Details: The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-13487, https://bbpress.org, https://codex.bbpress.org/releases, https://github.com/bbpress/bbPress, https://wordpress.org/plugins/bbpress/#developers, https://www.youtube.com/watch?v=3rXP8CGTe08
Affected packages
Package
Name: bbpress/bbpress
Purl: pkg:composer/bbpress/bbpress
Affected ranges
Type: ECOSYSTEM
Events:
