Stored Cross-Site Scripting in bbp Style Pack for WordPress
CVE-2026-101925

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

What is CVE-2026-101925?

The bbp Style Pack plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. Attackers with subscriber-level access can exploit this vulnerability by injecting malicious scripts through the 'display_name' and 'bbp_reply_content' parameters. By wrapping crafted replies in a block, attackers can bypass WordPress's automatic text formatting features, allowing the execution of their scripts whenever a user accesses the affected pages.

Affected Version(s)

bbp style pack 0 <= 6.4.8

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zickzick2
.