PT-2022-25283 · WordPress · Wpforo Forum
Ananda Dhakal
+1
·
Published
2022-11-08
·
Updated
2022-11-09
·
CVE-2022-40206
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
wpForo Forum plugin versions <= 2.0.5
Description
The issue is related to an insecure direct object references (IDOR) vulnerability. This vulnerability allows attackers with subscriber or higher user roles to mark any forum post as private or public.
Recommendations
For wpForo Forum plugin versions <= 2.0.5, update to a version higher than 2.0.5 to resolve the issue. As a temporary workaround, consider restricting user roles to prevent subscribers or higher from accessing the forum post settings until a patch is available.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpforo Forum