
CVE-2026-15010 The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feat… https://www.cve.org/CVERecord?id=CVE-2026-15010
Post summary
The bbp Style Pack plugin for WordPress is disclosed as vulnerable to stored XSS (CVE-2026-15010) in all versions up to 6.4.5, with no mention of PoC, exploitation, or patch information.
