Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 13 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Jul 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Robin-w
Robin-w bbp Style Pack Wordpress Wordpress wordpress |
|
| Vendors & Products |
Robin-w
Robin-w bbp Style Pack Wordpress Wordpress wordpress |
Sat, 11 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature. This is due to insufficient input sanitization in bsp_topic_fields_form_save() (which writes $_POST['bsp_topic_fields_label{n}'] directly to post meta via update_post_meta() with no filtering) and missing output escaping in bsp_topic_content_append_topic_fields() (which concatenates the stored meta value into an HTML <span> and echoes it via apply_filters/echo without esc_html()). This makes it possible for authenticated attackers, with Subscriber-level access and above (who have bbPress topic-creation privileges), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, including unauthenticated visitors. | |
| Title | bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-13T16:11:39.208Z
Reserved: 2026-07-07T21:52:36.970Z
Link: CVE-2026-15010
Updated: 2026-07-13T16:11:35.309Z
Status : Deferred
Published: 2026-07-11T07:16:46.033
Modified: 2026-07-13T17:17:01.803
Link: CVE-2026-15010
No data.
OpenCVE Enrichment
Updated: 2026-08-01T11:45:04Z