PT-2026-22475 · WordPress · Wpforo Forum

Scott Moore

·

Published

2026-02-28

·

Updated

2026-03-05

·

CVE-2026-28554

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions wpForo Forum version 2.4.14
Description The software contains a flaw due to missing authorization checks. An authenticated subscriber can approve or unapprove any forum post by exploiting the wpforo approve ajax AJAX handler. The check relies solely on a nonce, which can be bypassed by submitting a valid nonce along with an arbitrary post ID, effectively circumventing moderation controls.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the wpforo approve ajax handler to authorized personnel only.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28554

Affected Products

Wpforo Forum