Executive brief
The wpForo Forum plugin for WordPress, which adds community discussion features to websites, contains a security flaw that allows users with basic account access to delete files from the web server. By submitting specially crafted forum topic data, an attacker can trick the system into deleting critical configuration files or other site data. This can lead to a complete site outage or allow an attacker to reset the website's configuration to gain further control.
Technical details
The vulnerability stems from a two-step logic flaw in the topic_add() and topic_edit() action handlers, which accept arbitrary user-supplied data arrays from $_REQUEST and store them as postmeta without sufficient validation. An attacker can inject a malicious file path into the 'fileurl' field of the 'body' topic field. When a subsequent topic_edit request is made with the 'wpftcf_delete' parameter targeting that field, the plugin's add_file() method retrieves the poisoned path and passes it to wp_delete_file() without proper sanitization. This enables authenticated users (Subscriber and above) to delete any file writable by the PHP process, including wp-config.php. A patch is available in versions following 3.0.2.
Affected products
- gVectors Team wpForo Forum up to and including 3.0.2
Timeline
- 2026-04-11: disclosed
- 2026-04-11: advisory
References
- https://plugins.trac.wordpress.org/browser/wpforo/tags/3.0.2/classes/Actions.php
- https://plugins.trac.wordpress.org/browser/wpforo/tags/3.0.2/classes/Actions.php
- https://plugins.trac.wordpress.org/browser/wpforo/tags/3.0.2/classes/PostMeta.php
- https://plugins.trac.wordpress.org/browser/wpforo/tags/3.0.2/classes/PostMeta.php
- https://plugins.trac.wordpress.org/browser/wpforo/tags/3.0.2/classes/PostMeta.php
- https://plugins.trac.wordpress.org/browser/wpforo/tags/3.0.2/classes/Posts.php
- https://plugins.trac.wordpress.org/browser/wpforo/tags/3.0.2/includes/functions.php