WordPress bbPress Plugin <= 2.6.11 is vulnerable to Cross Site Request Forgery (CSRF)
bbPress
Minimum safe version
2.6.12
Update to 2.6.12 or later to address 17 fixable vulnerabilities
bbPress < 2.5.9 - Stored Cross-Site Scripting
bbPress <= 2.5.9 - Cross-Site Scripting
bbPress < 2.5.13 - Unauthenticated Blind SQL Injection
bbPress - Multiple Script Malformed Input Path Disclosure
bbPress - forum.php page Parameter SQL Injection
bbPress <= 2.5.8 - Stored Cross-Site Scripting (XSS)
bbPress <= 2.5.9 - Display Name & Avatar Potential Cross-Site Scripting (XSS)
bbPress <= 2.5.12 - Unauthenticated SQL Injection
bbPress < 2.6.0 - Subscriber+ Stored Cross-Site Scripting via Post Slug
bbPress 2.6-2.6.5 - Authenticated Privilege Escalation via the Super Moderator feature
WordPress bbPress Plugin - Multiple Vulnerabilities
WordPress bbPress Plugin <= 2.5.8 - Stored Cross Site Scripting
WordPress bbPress Plugin <= 2.5.9 - Cross Site Scripting
WordPress bbPress plugin <= 2.6.4 - Authenticated Privilege Escalation vulnerability
bbPress <= 2.6.4 - Authenticated (Admin+) Stored Cross-Site Scripting via the forums list table
WordPress bbPress plugin <= 2.6.4 - Unauthenticated Privilege Escalation vulnerability