wpForo Forum
cpe:2.3:a:gvectors:wpforo:*:*:*:*:wordpress:*:*, +1 more
- <= 2.4.14
A missing authorization vulnerability has been identified in wpForo Forum version 2.4.14. This vulnerability allows authenticated subscribers to approve or unapprove any forum post using the wpforo_approve_ajax AJAX handler. The issue arises because the nonce check is the only validation in place, enabling users to bypass moderation controls by submitting a valid nonce along with an arbitrary post ID.
Exploitation of this vulnerability allows for unauthorized approval or disapproval of forum posts, bypassing established moderation controls.
Users are advised to update to wpForo Forum version 2.4.16, which includes permission checks for post approval actions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.