Stored Cross-Site Scripting in bbp Style Pack for WordPress
CVE-2026-101925
6.4MEDIUM
What is CVE-2026-101925?
The bbp Style Pack plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. Attackers with subscriber-level access can exploit this vulnerability by injecting malicious scripts through the 'display_name' and 'bbp_reply_content' parameters. By wrapping crafted replies in a block, attackers can bypass WordPress's automatic text formatting features, allowing the execution of their scripts whenever a user accesses the affected pages.
Affected Version(s)
bbp style pack 0 <= 6.4.8