Executive brief
A security flaw has been identified in wpForo Forum, a popular community forum plugin for WordPress websites. This vulnerability allows unauthorized individuals to bypass security restrictions and perform administrative or high-level actions without permission. If exploited, an attacker could disrupt forum operations, modify content, or compromise the integrity of the community platform.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the wpForo Forum plugin for WordPress through version 3.0.6. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing sensitive functions. An unauthenticated remote attacker can exploit this by sending crafted network requests to perform actions that should be restricted to higher-privileged users. This can lead to unauthorized data modification or loss of service availability. The issue is resolved in version 3.0.7.
Affected products
- Tomdever wpForo Forum up to 3.0.6
Timeline
- 2026-04-18: other: Reported by Tiago Ventura (@perses)
- 2026-05-18: advisory: Patchstack published advisory
- 2026-06-01: disclosed: NVD published CVE record