wpForo Forum
cpe:2.3:a:gvectors:wpforo:*:*:*:*:wordpress:*:*, +1 more
- <= 2.4.14
A missing authorization vulnerability has been identified in wpForo Forum version 2.4.14. This vulnerability allows authenticated subscribers to manipulate forum topics by moving, merging, or splitting them using specific form action handlers. Attackers with a valid form nonce can reorganize forum content arbitrarily, without needing moderator permissions, and can even transfer topics to private forums.
Exploitation of this vulnerability could lead to unauthorized manipulation of forum topics, allowing users to disrupt discussions or hide content from public view by moving topics to private forums.
Users can update to wpForo Forum version 2.4.16, which includes added permission checks for topic management actions, to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.