Input validation vulnerability in bbPress 2.5.13

The bbPress plugin for WordPress is vulnerable to a security issue called blind SQL Injection. This means that a malicious user can access sensitive information from the database without needing to authenticate first. This vulnerability affects versions up to 2.5.12 of the plugin, as it is caused by inadequate escaping of user-supplied parameters and an insufficiently prepared SQL query.

Detected in:

bbPress fixed vulnerable versions: >= * < 2.5.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.