wpForo Forum Path Traversal Vulnerability Leading to Arbitrary File Deletion

Vulnerability

A vulnerability allowing arbitrary file deletion has been identified in the wpForo Forum plugin for WordPress, affecting all versions through 2.4.16. The issue arises from inadequate validation of file names and paths, which fails to prevent path traversal attacks. This vulnerability enables authenticated attackers with subscriber-level access or higher to delete arbitrary files on the server. Exploitation involves embedding a crafted path traversal string in the body of a forum post and subsequently deleting the post.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of files on the server.

Remediation

Users are advised to update the wpForo Forum plugin to version 2.4.17 or a newer patched version.

Added: Apr 4, 2026, 12:17 PM
Updated: Apr 4, 2026, 12:17 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
7.5
remediation
7.7
relevance
5.4
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.