Impact
The vulnerability is a missing authorization flaw in the wpForo Forum plugin, affecting all releases up to version 2.4.10, that allows an attacker to bypass access control levels and gain elevated privileges over forum management tasks. An exploited instance could lead to arbitrary reading, modification, or deletion of forum content and potentially override any administrative controls. The weakness corresponds to CWE‑862, Missing Authorization.
Affected Systems
WordPress sites that host the Tomdever wpForo Forum plugin, specifically any installation running a version from the original release through 2.4.10. No particular WordPress core or PHP version prerequisites are listed, so any environment that meets those plugin version constraints is susceptible.
Risk and Exploitability
The assigned CVSS score of 7.5 signals high severity, yet the EPSS score of less than 1 % indicates that current exploit activity is minimal. Exploitation will likely require the attacker to already possess some level of web access to the site, after which they can manipulate the plugin’s misconfigured access controls. The vulnerability is not included in the CISA KEV catalog, so no documented active exploitation is known, but the potential impact on confidentiality, integrity, and availability of forum data warrants proactive remediation.
OpenCVE Enrichment