rootpwn

medium · CVSS v3 6.4

CVE-2026-101925

The bbp style pack plugin for WordPress is vulnerable to stored XSS via display_name and bbp_reply_content. Authenticated users with subscri

Overview

The bbp style pack plugin for WordPress is vulnerable to stored XSS via display_name and bbp_reply_content. Authenticated users with subscriber-level access can inject scripts that execute when others view the reply. This flaw allows attackers to compromise user sessions and deface content.

Description

The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the attacker to wrap their crafted reply in a block, which prevents WordPress's wpautop/wptexturize processors from converting straight double quotes in the stored display name into typographic curly-quote entities that would otherwise neutralize the attribute-injection.

Impact

Confidentiality: attackers can inject scripts that may exfiltrate data or hijack sessions. Integrity: malicious content can be inserted into replies, defacing forums. Availability: minimal direct impact, but could degrade user trust. Impacted parties: all WordPress sites using bbp style pack plugin with subscriber-level accounts.

Remediation

Update bbp style pack plugin to the latest version (≥6.4.9) where input sanitization is fixed. If update not possible, disable or remove the plugin, or restrict subscriber-level access to reply posting. Apply a WAF rule to block XSS payloads in bbp_reply_content. Ensure WordPress core and bbPress are up to date.

Risk context

Medium severity (CVSS 6.4) indicates a moderate risk. Prompt patching is recommended to prevent potential XSS exploitation, especially on sites with active forums.

Affected products

  • WordPress bbp style pack plugin
  • WordPress 6.4.8
  • bbPress

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
6.4
CVSS v4
—
EPSS
—

wordpress xss bbp stored-xss subscriber plugin moderation wp-admin

← All CVEs