wpForo Forum
cpe:2.3:a:gvectors:wpforo:*:*:*:*:wordpress:*:*, +1 more
- <= 2.4.14
A missing authorization vulnerability has been identified in wpForo Forum version 2.4.14. This vulnerability allows authenticated subscribers to close or reopen any forum topic using the wpforo_close_ajax handler. By submitting a valid nonce along with an arbitrary topic ID, users can bypass the required moderator permissions, potentially disrupting ongoing forum discussions.
Exploitation of this vulnerability allows for unauthorized modification of forum topic statuses, which could disrupt discussions and community engagement.
Users can update to wpForo Forum version 2.4.16, which includes added permission checks for topic management actions. After updating, it is recommended to delete all caches and purge CDN if used.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.