wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split any forum topic via the topic_move, topic_merge, and topic_split form action handlers. Attackers with a valid form nonce can reorganize arbitrary forum content without moderator permissions, including relocating topics to private forums.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 28 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split any forum topic via the topic_move, topic_merge, and topic_split form action handlers. Attackers with a valid form nonce can reorganize arbitrary forum content without moderator permissions, including relocating topics to private forums. | |
| Title | wpForo Forum 2.4.14 Missing Authorization via Topic Management Form Handlers | |
| First Time appeared |
Gvectors
Gvectors wpforo Forum |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:*:*:* cpe:2.3:a:gvectors:wpforo_forum:2.4.16:*:*:*:*:*:*:* |
|
| Vendors & Products |
Gvectors
Gvectors wpforo Forum |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-28T21:47:36.466Z
Reserved: 2026-02-28T18:54:23.280Z
Link: CVE-2026-28556
No data.
Status : Received
Published: 2026-02-28T22:16:02.220
Modified: 2026-02-28T22:16:02.220
Link: CVE-2026-28556
No data.
OpenCVE Enrichment
No data.
Weaknesses