PT-2026-22480 · WordPress · Wpforo Forum
Scott Moore
·
Published
2026-02-28
·
Updated
2026-03-04
·
CVE-2026-28559
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
wpForo Forum version 2.4.14
Description
The software contains an information disclosure issue that allows unauthenticated users to retrieve private and unapproved forum topics. This is possible through the global RSS feed endpoint. When requesting the RSS feed without a forum ID parameter, the privacy and status restrictions are bypassed, as the query does not apply the necessary WHERE clauses. The vulnerable endpoint is
/wp-content/plugins/wpforo/rss.php. The issue allows unauthorized access to forum topics.Recommendations
Apply a fix to ensure the privacy and status WHERE clauses are correctly applied when a forum ID parameter is not provided to the
/wp-content/plugins/wpforo/rss.php endpoint.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpforo Forum