Impact
XenForo versions prior to 2.3.13 contain a missing authorization flaw in the ACP cache‑rebuild dispatcher. Administrators with only the rebuildCache permission can POST a job class and actor user ID to the dispatcher, causing the system to execute an approval‑queue job on behalf of an arbitrary user. This allows the administrator to approve queued registrations without holding the required approval‑queue or moderator privileges, and the action is logged under the impersonated account, effectively bypassing normal moderation controls.
Affected Systems
XenForo XenForo installations running any version earlier than 2.3.13 are impacted. The vulnerability applies to the standard XenForo forum software; no add‑on or platform specifics beyond the core product are listed.
Risk and Exploitability
The flaw has a CVSS score of 5.1, indicating moderate severity. Exploitability requires an authenticated user with rebuildCache permission; it does not allow remote code execution or arbitrary file disclosure. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Because the attacker can impersonate users and manipulate the moderation log, the risk is significant enough for administrators to apply the patch promptly, especially in environments that rely heavily on approval queues for new user registrations.
OpenCVE Enrichment