CVE-2020-13487: XSS
Published May 26, 2020
·Updated
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?posttype=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.
Affected Software
2 affected components
composer/bbpress/bbpress<=2.6.4
bbPress Bbpress Wordpress<=2.6.4
Event History
May 26, 2020
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:18 PM