Junglewise Threat Intelligence

CVE-2026-91092: wpForo Forum authorization bypass in post editing

CVE-2026-91092 · Severity: medium · CVSS 4.3 · Published 2026-09-22

Technologies: wpForo Forum. Vendors: wpForo.

Executive brief

The wpForo Forum plugin for WordPress does not properly verify user permissions when editing forum posts. An authenticated user with subscriber-level access can modify guest author posts—including title, body, author name, and associated email address—if guest posting and editing features are enabled. This allows account takeover of guest authorship and potential reputation damage or content manipulation.

Technical details

The vulnerability is an authorization bypass in post editing functionality affecting wpForo versions up to 3.1.5. An authenticated subscriber can edit guest-authored posts by supplying the target guest author's email address, due to insufficient permission checks in the Actions.php and Members.php classes. Exploitation requires guest posting/editing to be enabled; the attacker must know the guest email address.

Affected products

  • wpForo wpForo Forum up to and including 3.1.5

Timeline

  • 2026-09-22: disclosed

References

Related threats