Search
Find a vulnerability
Search criteria
4 vulnerabilities by robin-w
CVE-2026-101925 (GCVE-0-2026-101925)
Vulnerability from nvd – Published: 2026-10-01 08:28 – Updated: 2026-10-01 18:21
VLAI
EPSS
VEX
Title
bbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name
Summary
The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the attacker to wrap their crafted reply in a <pre> block, which prevents WordPress's wpautop/wptexturize processors from converting straight double quotes in the stored display name into typographic curly-quote entities that would otherwise neutralize the attribute-injection.
Severity
6.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:21 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
7 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| robin-w | bbp style pack |
Affected:
0 , ≤ 6.4.8
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101925",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:21:15.523000Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:21:22.142Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "bbp style pack",
"vendor": "robin-w",
"versions": [
{
"lessThanOrEqual": "6.4.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "zickzick2"
}
],
"descriptions": [
{
"lang": "en",
"value": "The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u0027display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)\u0027 parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the attacker to wrap their crafted reply in a \u0026lt;pre\u0026gt; block, which prevents WordPress\u0027s wpautop/wptexturize processors from converting straight double quotes in the stored display name into typographic curly-quote entities that would otherwise neutralize the attribute-injection."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:43.363Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/31c9b86b-c971-4a0b-95ef-10bc7781e93f?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L249"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L223"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L244"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L83"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L275"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3719484%40bbp-style-pack\u0026new=3719484%40bbp-style-pack"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-28T16:19:12.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:12:56.000Z",
"value": "Disclosed"
}
],
"title": "bbp style pack \u003c= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-101925",
"datePublished": "2026-10-01T08:28:43.363Z",
"dateReserved": "2026-09-28T16:04:07.165Z",
"dateUpdated": "2026-10-01T18:21:22.142Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15010 (GCVE-0-2026-15010)
Vulnerability from nvd – Published: 2026-07-11 06:50 – Updated: 2026-07-13 16:11
VLAI
EPSS
VEX
Title
bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields
Summary
The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature. This is due to insufficient input sanitization in bsp_topic_fields_form_save() (which writes $_POST['bsp_topic_fields_label{n}'] directly to post meta via update_post_meta() with no filtering) and missing output escaping in bsp_topic_content_append_topic_fields() (which concatenates the stored meta value into an HTML <span> and echoes it via apply_filters/echo without esc_html()). This makes it possible for authenticated attackers, with Subscriber-level access and above (who have bbPress topic-creation privileges), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, including unauthenticated visitors.
Severity
6.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-13 16:11 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| robin-w | bbp style pack |
Affected:
0 , ≤ 6.4.5
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-15010",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-13T16:11:32.202615Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-13T16:11:39.208Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "bbp style pack",
"vendor": "robin-w",
"versions": [
{
"lessThanOrEqual": "6.4.5",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Catalin Oancea (0x4D5A)"
}
],
"descriptions": [
{
"lang": "en",
"value": "The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature. This is due to insufficient input sanitization in bsp_topic_fields_form_save() (which writes $_POST[\u0027bsp_topic_fields_label{n}\u0027] directly to post meta via update_post_meta() with no filtering) and missing output escaping in bsp_topic_content_append_topic_fields() (which concatenates the stored meta value into an HTML \u003cspan\u003e and echoes it via apply_filters/echo without esc_html()). This makes it possible for authenticated attackers, with Subscriber-level access and above (who have bbPress topic-creation privileges), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, including unauthenticated visitors."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-11T06:50:33.433Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f898ab34-2d63-458d-b19b-4e2b6f4a0f3b?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.5/includes/functions_topic_fields.php#L146"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.5/includes/functions_topic_fields.php#L235"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3601461%40bbp-style-pack\u0026new=3601461%40bbp-style-pack"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-09T07:13:27.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-07-10T17:38:23.000Z",
"value": "Disclosed"
}
],
"title": "bbp style pack \u003c= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-15010",
"datePublished": "2026-07-11T06:50:33.433Z",
"dateReserved": "2026-07-07T21:52:36.970Z",
"dateUpdated": "2026-07-13T16:11:39.208Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101925 (GCVE-0-2026-101925)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 18:21
VLAI
EPSS
VEX
Title
bbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name
Summary
The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the attacker to wrap their crafted reply in a <pre> block, which prevents WordPress's wpautop/wptexturize processors from converting straight double quotes in the stored display name into typographic curly-quote entities that would otherwise neutralize the attribute-injection.
Severity
6.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:21 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
7 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| robin-w | bbp style pack |
Affected:
0 , ≤ 6.4.8
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101925",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:21:15.523000Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:21:22.142Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "bbp style pack",
"vendor": "robin-w",
"versions": [
{
"lessThanOrEqual": "6.4.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "zickzick2"
}
],
"descriptions": [
{
"lang": "en",
"value": "The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u0027display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)\u0027 parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the attacker to wrap their crafted reply in a \u0026lt;pre\u0026gt; block, which prevents WordPress\u0027s wpautop/wptexturize processors from converting straight double quotes in the stored display name into typographic curly-quote entities that would otherwise neutralize the attribute-injection."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:43.363Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/31c9b86b-c971-4a0b-95ef-10bc7781e93f?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L249"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L223"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L244"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L83"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L275"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3719484%40bbp-style-pack\u0026new=3719484%40bbp-style-pack"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-28T16:19:12.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:12:56.000Z",
"value": "Disclosed"
}
],
"title": "bbp style pack \u003c= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-101925",
"datePublished": "2026-10-01T08:28:43.363Z",
"dateReserved": "2026-09-28T16:04:07.165Z",
"dateUpdated": "2026-10-01T18:21:22.142Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15010 (GCVE-0-2026-15010)
Vulnerability from cvelistv5 – Published: 2026-07-11 06:50 – Updated: 2026-07-13 16:11
VLAI
EPSS
VEX
Title
bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields
Summary
The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature. This is due to insufficient input sanitization in bsp_topic_fields_form_save() (which writes $_POST['bsp_topic_fields_label{n}'] directly to post meta via update_post_meta() with no filtering) and missing output escaping in bsp_topic_content_append_topic_fields() (which concatenates the stored meta value into an HTML <span> and echoes it via apply_filters/echo without esc_html()). This makes it possible for authenticated attackers, with Subscriber-level access and above (who have bbPress topic-creation privileges), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, including unauthenticated visitors.
Severity
6.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-13 16:11 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| robin-w | bbp style pack |
Affected:
0 , ≤ 6.4.5
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-15010",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-13T16:11:32.202615Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-13T16:11:39.208Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "bbp style pack",
"vendor": "robin-w",
"versions": [
{
"lessThanOrEqual": "6.4.5",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Catalin Oancea (0x4D5A)"
}
],
"descriptions": [
{
"lang": "en",
"value": "The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature. This is due to insufficient input sanitization in bsp_topic_fields_form_save() (which writes $_POST[\u0027bsp_topic_fields_label{n}\u0027] directly to post meta via update_post_meta() with no filtering) and missing output escaping in bsp_topic_content_append_topic_fields() (which concatenates the stored meta value into an HTML \u003cspan\u003e and echoes it via apply_filters/echo without esc_html()). This makes it possible for authenticated attackers, with Subscriber-level access and above (who have bbPress topic-creation privileges), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, including unauthenticated visitors."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-11T06:50:33.433Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f898ab34-2d63-458d-b19b-4e2b6f4a0f3b?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.5/includes/functions_topic_fields.php#L146"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.5/includes/functions_topic_fields.php#L235"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3601461%40bbp-style-pack\u0026new=3601461%40bbp-style-pack"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-09T07:13:27.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-07-10T17:38:23.000Z",
"value": "Disclosed"
}
],
"title": "bbp style pack \u003c= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-15010",
"datePublished": "2026-07-11T06:50:33.433Z",
"dateReserved": "2026-07-07T21:52:36.970Z",
"dateUpdated": "2026-07-13T16:11:39.208Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}