Impact
The wpForo Forum WordPress plugin, versions prior to 3.1.6, fails to verify the origin of client‑supplied IP address headers. It uses these headers to enforce a per‑visitor rate limit on paid AI requests. An unauthenticated attacker can spoof the IP header, bypass the limit, and send unlimited requests, depleting the site owner's metered AI credits. This flaw is a form of improper input validation (CWE-20) that leads to resource exhaustion, with potential financial impact but no direct compromise of confidentiality or integrity.
Affected Systems
Affected systems are WordPress sites running the wpForo Forum plugin in any version from 3.0.0 up to and including 3.1.5. The vulnerability is vendor‑owned, and there is no official patch listing in the CVE data except the implication that versions before 3.1.6 are vulnerable.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity. No EPSS data is available and it is not listed in the KEV catalog. Attackers need only craft HTTP requests with a forged IP header; no authentication is required. The exploit path is straightforward for anyone with internet access to the site, making the risk tangible for sites that rely on paid AI services.
OpenCVE Enrichment