wpForo Forum
cpe:2.3:a:gvectors:wpforo:*:*:*:*:wordpress:*:*, +1 more
- <= 2.4.14
A vulnerability in wpForo Forum versions through 2.4.14 allows authenticated users to exploit a missing capability check. This vulnerability enables users to trigger bulk reassignment of wpForo usergroups through the wpforo_synch_roles AJAX handler. By accessing the usergroups admin page, which is available to all authenticated users, attackers can obtain a nonce and then remap wpForo usergroups to arbitrary WordPress roles.
Exploitation of this vulnerability could lead to unauthorized changes in user roles, allowing users to gain elevated privileges or access rights they should not have.
Users can update to wpForo Forum version 2.4.16 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.