The wpForo Forum plugin for WordPress versions up to 2.4.16 contains a variable overwrite vulnerability in the post editing functionality caused by insecure use of the extract() function on user-controlled input. An attacker can inject malicious parameters through the $_REQUEST['post'] array to bypass permission checks that normally restrict post editing capabilities. This affects all installations using the vulnerable plugin versions. The vulnerability has a CVSS score of 6.5 (Medium severity) with a network-based attack vector requiring low complexity and only low-level privileges (Subscriber access or above). While no code execution is possible, the impact is significant as authenticated attackers can modify the title, body, name, and email fields of any forum post regardless of access restrictions, including posts in private forums and posts authored by administrators or moderators. The attack is made more feasible by a hardcoded nonce that can be obtained by viewing any forum page. Current exploitation status shows minimal community attention with an EPSS score of 0.0001, indicating this vulnerability is not being actively exploited in the wild. There is no evidence of public exploit code availability or listing on the Known Exploited Vulnerabilities catalog. However, organizations running wpForo should treat this as a privilege escalation risk and apply patches promptly, particularly for installations hosting sensitive forum discussions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Tomdever | WpForo Forum | >= 0, <= 2.4.16CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.