PT-2022-25282 · WordPress · Wpforo Forum
Ananda Dhakal
+1
·
Published
2022-11-08
·
Updated
2022-11-09
·
CVE-2022-40205
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
wpForo Forum plugin versions <= 2.0.5
Description
The issue is related to an insecure direct object references (IDOR) vulnerability. This vulnerability allows attackers with subscriber or higher user roles to mark any forum post as solved or unsolved.
Recommendations
For wpForo Forum plugin versions <= 2.0.5, update to a version higher than 2.0.5 to resolve the issue. As a temporary workaround, consider restricting the ability to mark posts as solved or unsolved to higher user roles until a patch is available.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpforo Forum