WordPress Plugin Vulnerabilities

bbPress < 2.6.0 - Subscriber+ Stored Cross-Site Scripting via Post Slug

Description

Due to the way post slugs are handled, low privileged users could perform Cross-Site Scripting attacks against admins

Affects Plugins

Fixed in 2.6.0

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Karim El Ouerghemmi and Simon Scannell of SonarSource
Verified
Yes

Timeline

Publicly Published
2019-11-12 (about 6 years ago)
Added
2022-01-12 (about 4 years ago)
Last Updated
2022-04-12 (about 3 years ago)

Other