CVE-2020-13693 describes an unauthenticated privilege escalation vulnerability in the bbPress plugin for WordPress, affecting versions prior to 2.6.5, specifically when New User Registration is enabled. This critical flaw, with a CVSS score of 9.8, allows an attacker to gain elevated privileges without authentication, posing a significant risk of complete compromise (confidentiality, integrity, and availability). While not listed on the KEV catalog, public exploit code exists on ExploitDB, and it has garnered some community discussion and media coverage, indicating awareness of its exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.5CPE matchmatch criteria | cpe:2.3:a:bbpress:bbpress:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.