PT-2022-25282 · WordPress · Wpforo Forum

Ananda Dhakal

+1

·

Published

2022-11-08

·

Updated

2022-11-09

·

CVE-2022-40205

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions wpForo Forum plugin versions <= 2.0.5
Description The issue is related to an insecure direct object references (IDOR) vulnerability. This vulnerability allows attackers with subscriber or higher user roles to mark any forum post as solved or unsolved.
Recommendations For wpForo Forum plugin versions <= 2.0.5, update to a version higher than 2.0.5 to resolve the issue. As a temporary workaround, consider restricting the ability to mark posts as solved or unsolved to higher user roles until a patch is available.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2022-40205

Affected Products

Wpforo Forum