Description
The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.
Published: 2026-08-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The wpForo Forum WordPress plugin before version 3.1.3 contains a mass assignment flaw that allows any registered subscriber to write administrator-controlled profile fields, including account status and reputation. This weakness permits a low‑privileged user to activate a pending or banned account, elevate privileges, and forge their forum reputation score, undermining the forum’s integrity and access control.

Affected Systems

Sites running the wpForo Forum plugin prior to 3.1.3 are affected. The plugin is distributed under the vendor Unknown:wpForo Forum and is used on WordPress installations worldwide. The flaw targets the profile update functionality available to subscriber‑level users.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.3 indicates moderate severity, yet the potential for privilege escalation remains a significant concern. The likely attack vector is a legitimate subscriber account used to submit a profile update request that includes privileged fields, or a freshly created subscriber account used to repeatedly attempt mass assignment. The vulnerability can be exploited with minimal effort and no special conditions beyond having a subscriber role.

Generated by OpenCVE AI on August 4, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade wpForo Forum to version 3.1.3 or later
  • Remove or deny subscribers the ability to edit reputation and account‑state fields by adjusting role capabilities
  • As a temporary measure, block profile updates that attempt to modify privileged fields using custom code or a plugin that restricts mass assignment

Generated by OpenCVE AI on August 4, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.
Title wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T14:29:45.722Z

Reserved: 2026-06-19T09:26:25.586Z

Link: CVE-2026-12698

cve-icon Vulnrichment

Updated: 2026-08-04T14:28:42.422Z

cve-icon NVD

Status : Received

Published: 2026-08-04T07:16:28.487

Modified: 2026-08-04T15:16:24.973

Link: CVE-2026-12698

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:00:11Z

Weaknesses