Executive brief
wpForo Forum is a popular discussion board plugin for WordPress websites. A critical security flaw allows unauthenticated attackers to bypass authentication mechanisms, potentially gaining full administrative access to the website. This could lead to complete site takeover, data theft, or the injection of malicious content.
Technical details
The wpForo Forum plugin for WordPress is vulnerable to an authentication bypass (CWE-288) in versions up to and including 3.1.0. The vulnerability stems from a broken authentication mechanism that allows an unauthenticated remote attacker to perform actions that should be restricted to high-privileged users. By exploiting an alternate path or channel, an attacker can potentially escalate privileges to an administrator account. This vulnerability is highly automatable and requires no user interaction. A fix is available in version 3.1.1.
Affected products
- Tomdever wpForo Forum <= 3.1.0
Timeline
- 2026-05-21: other: Vulnerability reported by Jakub Herman
- 2026-06-04: advisory: Initial advisory published by Patchstack
- 2026-06-17: disclosed: CVE published to NVD
- 2026-06-17: patched: Patch confirmed available in version 3.1.1