Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4666

23
FAUCET Score

The wpForo Forum plugin for WordPress versions up to 2.4.16 contains a variable overwrite vulnerability in the post editing functionality caused by insecure use of the extract() function on user-controlled input. An attacker can inject malicious parameters through the $_REQUEST['post'] array to bypass permission checks that normally restrict post editing capabilities. This affects all installations using the vulnerable plugin versions. The vulnerability has a CVSS score of 6.5 (Medium severity) with a network-based attack vector requiring low complexity and only low-level privileges (Subscriber access or above). While no code execution is possible, the impact is significant as authenticated attackers can modify the title, body, name, and email fields of any forum post regardless of access restrictions, including posts in private forums and posts authored by administrators or moderators. The attack is made more feasible by a hardcoded nonce that can be obtained by viewing any forum page. Current exploitation status shows minimal community attention with an EPSS score of 0.0001, indicating this vulnerability is not being actively exploited in the wild. There is no evidence of public exploit code availability or listing on the Known Exploited Vulnerabilities catalog. However, organizations running wpForo should treat this as a privilege escalation risk and apply patches promptly, particularly for installations hosting sensitive forum discussions.

Impacted Technologies

VendorProductVersion(s)CPE
TomdeverWpForo Forum
>= 0, <= 2.4.16CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
25.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0033 is in the 34th percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/wpforo/tags/2.4.16/classes/Actions.php
plugins.trac.wordpress.org / browser/wpforo/tags/2.4.16/classes/Posts.php
plugins.trac.wordpress.org / browser/wpforo/tags/2.4.16/classes/Posts.php
plugins.trac.wordpress.org / browser/wpforo/tags/2.4.16/includes/functions.php
plugins.trac.wordpress.org / changeset
ti.wordfence.io / vendors/patch/1885/download
wordpress.org / plugins/wpforo
wordfence.com / threat-intel/vulnerabilities/id/049ffab1-677d-4112-9f1d-092ee01299f1