wpForo Forum
cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:wordpress:*:*
- <= 2.4.16
A vulnerability allowing arbitrary file deletion has been identified in the wpForo Forum plugin for WordPress, affecting all versions through 2.4.16. The issue arises from inadequate validation of file names and paths, which fails to prevent path traversal attacks. This vulnerability enables authenticated attackers with subscriber-level access or higher to delete arbitrary files on the server. Exploitation involves embedding a crafted path traversal string in the body of a forum post and subsequently deleting the post.
Exploitation of this vulnerability allows for unauthorized deletion of files on the server.
Users are advised to update the wpForo Forum plugin to version 2.4.17 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.