PT-2022-25283 · WordPress · Wpforo Forum

Ananda Dhakal

+1

·

Published

2022-11-08

·

Updated

2022-11-09

·

CVE-2022-40206

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions wpForo Forum plugin versions <= 2.0.5
Description The issue is related to an insecure direct object references (IDOR) vulnerability. This vulnerability allows attackers with subscriber or higher user roles to mark any forum post as private or public.
Recommendations For wpForo Forum plugin versions <= 2.0.5, update to a version higher than 2.0.5 to resolve the issue. As a temporary workaround, consider restricting user roles to prevent subscribers or higher from accessing the forum post settings until a patch is available.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2022-40206

Affected Products

Wpforo Forum