CVE-2020-13693: bbPress unauthenticated privilege-escalation
9.8
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.97363%
CWE
Published
5/24/2022
Updated
4/25/2024
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| bbpress/bbpress | composer | < 2.6.5 | 2.6.5 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from improper privilege management during user registration. Key observations:
- The exploit requires 'New User Registration' to be enabled, implicating registration flow functions.
- CWE-269 indicates flawed role assignment logic.
- bbPress 2.6.5's release notes specifically mention privilege escalation fixes in registration/auth systems.
- The unauthenticated nature suggests functions processing registration requests lacked:
- Role parameter sanitization
- Authorization checks for role assignment
- Enforcement of WordPress's default role settings Functions like bbp_create_user (registration handler) and bbp_set_user_default_role (role assignment) would be primary candidates for these flaws, consistent with WordPress plugin vulnerability patterns.