Impact
An unauthenticated broken access control flaw exists in WordPress wpForo Forum versions prior to 3.0.2. Because the plugin does not enforce proper authorization checks on privileged operations, an attacker can gain access to administrative functions or perform actions reserved for higher‑privileged users. The weakness is classified as CWE-281, which highlights improper authorization. The potential impact includes unauthorized modifications to forum content, installation of malicious plugins, or manipulation of user accounts, all of which threaten the confidentiality, integrity, and availability of the WordPress installation.
Affected Systems
The vulnerable product is the WordPress wpForo Forum plugin distributed by Tomdever. All installations running a version older than 3.0.2 are affected, regardless of the WordPress core version or hosting environment.
Risk and Exploitability
The CVSS score of 7.5 points to a high severity vulnerability that can have significant security consequences. The EPSS score is below 1%, indicating that at the time of analysis the likelihood of exploitation is low, but the flaw remains a valid threat. It is not listed in CISA's KEV catalog. Because the flaw is unauthenticated, an attacker may exploit it from any network location with access to the forum’s web interface, typically by sending crafted HTTP requests to privileged endpoints that lack proper authorization checks.
OpenCVE Enrichment