VYPR

Turnkey bbPress by WeaverTheme

by WordPress

CVEs (2)

  • CVE-2026-10035MedAug 16, 2026
    risk 0.43cvss 6.6epss 0.00

    The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached through the wvrbbp_save_restore()…

  • CVE-2024-12221MedJan 4, 2025
    risk 0.33cvss 6.1epss 0.00

    The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonce’ parameter in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for…