medium · CVSS v3 6.4
CVE-2026-101925
The bbp style pack plugin for WordPress is vulnerable to stored XSS via display_name and bbp_reply_content. Authenticated users with subscri
Overview
The bbp style pack plugin for WordPress is vulnerable to stored XSS via display_name and bbp_reply_content. Authenticated users with subscriber-level access can inject scripts that execute when others view the reply. This flaw allows attackers to compromise user sessions and deface content.
Description
The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the attacker to wrap their crafted reply in a block, which prevents WordPress's wpautop/wptexturize processors from converting straight double quotes in the stored display name into typographic curly-quote entities that would otherwise neutralize the attribute-injection.
Impact
Confidentiality: attackers can inject scripts that may exfiltrate data or hijack sessions. Integrity: malicious content can be inserted into replies, defacing forums. Availability: minimal direct impact, but could degrade user trust. Impacted parties: all WordPress sites using bbp style pack plugin with subscriber-level accounts.
Remediation
Update bbp style pack plugin to the latest version (≥6.4.9) where input sanitization is fixed. If update not possible, disable or remove the plugin, or restrict subscriber-level access to reply posting. Apply a WAF rule to block XSS payloads in bbp_reply_content. Ensure WordPress core and bbPress are up to date.
Risk context
Medium severity (CVSS 6.4) indicates a moderate risk. Prompt patching is recommended to prevent potential XSS exploitation, especially on sites with active forums.
Affected products
- WordPress bbp style pack plugin
- WordPress 6.4.8
- bbPress
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 6.4
- CVSS v4
- —
- EPSS
- —