CVE-2026-62137: WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerability
Published Sep 11, 2026
·Updated
Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.
Affected Software
1 affected component
bbPress<=2.6.14
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/bbpressto a version that resolves this vulnerability.Fixed in 2.6.15
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress or bbPress account to attempt exploitation. The network attack vector indicates it can be reached remotely.
2
What security impact is reported?
The reported impact is limited to confidentiality: sensitive data may be exposed. No integrity or availability impact is identified in the supplied severity vector.
3
Which bbPress versions are affected?
bbPress versions 2.6.14 and earlier are identified as affected.