Medium severity4.8NVD Advisory· Published May 26, 2020· Updated Jun 17, 2026
CVE-2020-13487
CVE-2020-13487
Description
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bbpress/bbpressPackagist | <= 2.6.4 | — |
Affected products
3- WordPress/bbPress plugindescription
Patches
Vulnerability mechanics
References
8- www.youtube.com/watchnvdExploitThird Party AdvisoryWEB
- bbpress.orgnvdVendor Advisory
- codex.bbpress.org/releases/nvdVendor Advisory
- github.com/advisories/GHSA-p9xp-xghp-gqvpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-13487ghsaADVISORY
- wordpress.org/plugins/bbpress/nvdThird Party AdvisoryWEB
- bbpress.orgghsaWEB
- codex.bbpress.org/releasesghsaWEB
News mentions
0No linked articles in our index yet.