Executive brief
wpForo Forum is a popular WordPress plugin that adds discussion forum functionality to WordPress sites. A vulnerability in versions before 3.1.3 allows ordinary subscriber-level members to manipulate their own account status and reputation scores by injecting hidden administrator-controlled fields during profile updates. An attacker can self-activate a banned or pending account, forge reputation points, and confirm their email address without authorization—effectively bypassing account restrictions and reputation systems that moderators rely on.
Technical details
This is a broken access control vulnerability (mass assignment / over-posting) in the wpForo profile update handler. The vulnerable component fails to whitelist which fields a member may modify when editing their own profile; instead, it accepts and persists any field passed in the POST request (member[status], member[custom_points], member[is_email_confirmed], etc.) without validation. The attack requires the attacker to hold a subscriber-level account and have at least 3 approved forum posts (default threshold), which is self-achievable through normal participation. The attacker then crafts a profile update request containing both legitimate fields and injected admin-controlled fields, using a valid CSRF nonce and same-origin Referer. No further privilege is needed—the injected values are written directly to the database. Notably, role-bearing fields (groupid, secondary_groupids) are separately guarded and cannot be escalated. The vulnerability was patched in version 3.1.3.
Affected products
- wpForo wpForo Forum before 3.1.3
Timeline
- 2026-07-27: disclosed: Publicly published on WPScan
- 2026-07-27: patched: Fixed in version 3.1.3
- 2026-08-04: advisory: Published to NVD