Vulnerability record · CVE-2020-13487 · published 26 May 2020
CVE-2020-13487: Bbpress cross-site scripting vulnerability
Bbpress · Bbpress
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.
Description
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bbpress.org/ | Vendor Advisory |
| https://codex.bbpress.org/releases/ | Vendor Advisory |
| https://wordpress.org/plugins/bbpress/#developers | Third Party Advisory |
| https://www.youtube.com/watch?v=3rXP8CGTe08 | ExploitThird Party Advisory |
| https://bbpress.org/ | Vendor Advisory |
| https://codex.bbpress.org/releases/ | Vendor Advisory |
| https://wordpress.org/plugins/bbpress/#developers | Third Party Advisory |
| https://www.youtube.com/watch?v=3rXP8CGTe08 | ExploitThird Party Advisory |
Track CVE-2020-13487 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13487), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.