Impact
The wpForo Forum WordPress plugin before version 3.1.3 contains a mass assignment flaw that allows any registered subscriber to write administrator-controlled profile fields, including account status and reputation. This weakness permits a low‑privileged user to activate a pending or banned account, elevate privileges, and forge their forum reputation score, undermining the forum’s integrity and access control.
Affected Systems
Sites running the wpForo Forum plugin prior to 3.1.3 are affected. The plugin is distributed under the vendor Unknown:wpForo Forum and is used on WordPress installations worldwide. The flaw targets the profile update functionality available to subscriber‑level users.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.3 indicates moderate severity, yet the potential for privilege escalation remains a significant concern. The likely attack vector is a legitimate subscriber account used to submit a profile update request that includes privileged fields, or a freshly created subscriber account used to repeatedly attempt mass assignment. The vulnerability can be exploited with minimal effort and no special conditions beyond having a subscriber role.
OpenCVE Enrichment