CVE-2026-74010
Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14.
- Published Aug 31, 2026
- CVSS 5.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)