Junglewise Threat Intelligence

CVE-2026-12698: WordPress wpForo Forum privilege escalation via profile field mass assignment

CVE-2026-12698 · Severity: medium · CVSS 4.3 · Published 2026-08-04

Technologies: wpForo Forum. Vendors: wpForo.

Executive brief

wpForo Forum is a popular WordPress plugin that adds discussion forum functionality to WordPress sites. A vulnerability in versions before 3.1.3 allows ordinary subscriber-level members to manipulate their own account status and reputation scores by injecting hidden administrator-controlled fields during profile updates. An attacker can self-activate a banned or pending account, forge reputation points, and confirm their email address without authorization—effectively bypassing account restrictions and reputation systems that moderators rely on.

Technical details

This is a broken access control vulnerability (mass assignment / over-posting) in the wpForo profile update handler. The vulnerable component fails to whitelist which fields a member may modify when editing their own profile; instead, it accepts and persists any field passed in the POST request (member[status], member[custom_points], member[is_email_confirmed], etc.) without validation. The attack requires the attacker to hold a subscriber-level account and have at least 3 approved forum posts (default threshold), which is self-achievable through normal participation. The attacker then crafts a profile update request containing both legitimate fields and injected admin-controlled fields, using a valid CSRF nonce and same-origin Referer. No further privilege is needed—the injected values are written directly to the database. Notably, role-bearing fields (groupid, secondary_groupids) are separately guarded and cannot be escalated. The vulnerability was patched in version 3.1.3.

Affected products

  • wpForo wpForo Forum before 3.1.3

Timeline

  • 2026-07-27: disclosed: Publicly published on WPScan
  • 2026-07-27: patched: Fixed in version 3.1.3
  • 2026-08-04: advisory: Published to NVD

References