Junglewise Threat Intelligence

CVE-2026-40767: gVectors wpForo Forum broken access control

CVE-2026-40767 · Severity: high · CVSS 7.5 · Published 2026-06-15

Technologies: gVectors Team wpForo Forum. Vendors: gVectors Team.

Executive brief

wpForo Forum is a popular community forum plugin for WordPress websites. A security flaw in versions prior to 3.0.2 allows unauthorized individuals to bypass access controls and potentially view sensitive information that should be restricted. This could lead to the exposure of private forum data or user information, impacting the privacy and integrity of the community platform.

Technical details

A broken access control vulnerability exists in the wpForo Forum plugin for WordPress due to improper preservation of permissions (CWE-281). The flaw allows an unauthenticated remote attacker to bypass authorization checks that should restrict access to specific functions or data. According to the CVSS vector, the impact is limited to high confidentiality loss, suggesting that attackers can read sensitive data but cannot necessarily modify it or crash the service. The vulnerability is resolved in version 3.0.2.

Affected products

  • gVectors Team wpForo Forum < 3.0.2

Timeline

  • 2026-03-04: other: Reported by researcher Dahmani Toumi
  • 2026-04-21: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: NVD publication date

References

Related threats