Impact
The wpForo Forum plugin contains a Missing Authorization flaw (CWE‑862) that allows an attacker to access or manipulate forum sections that should be locked behind proper authentication. This can enable unauthorized changes, data exposure, or administrative functions without permission.
Affected Systems
The vulnerability affects the Tomdever wpForo Forum plugin for WordPress. Any installation of the plugin up through version 3.0.6 is impacted; versions beyond this have been patched.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity, and the absence of an EPSS score means that the exploitation probability is currently unknown but could be significant. The description suggests the flaw can be exploited through the web interface, and it is inferred that an attacker might remotely request the privileged area once the access control is bypassed. However, this inference is not explicitly confirmed in the payload and may require further evidence.
OpenCVE Enrichment