PT-2026-33825 · WordPress · Wpforo Forum+1

Jude Nwadinobi

+1

·

Published

2026-04-20

·

Updated

2026-04-27

·

CVE-2026-6248

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions wpForo Forum versions prior to 3.0.6
Description The plugin is subject to arbitrary file deletion. This occurs because the Members::update() method fails to validate or restrict values for file-type custom profile fields, enabling authenticated users to store arbitrary paths. Additionally, the wpforo fix upload dir() sanitization function within ucf file delete() only remaps paths matching a specific pattern before they are passed to the unlink() function. Authenticated attackers with subscriber-level access or higher can exploit this to delete arbitrary files on the server, which may lead to remote code execution if critical files like 'wp-config.php' are removed. This issue requires the wpForo - User Custom Fields addon plugin to be active.
Recommendations Update to a version newer than 3.0.5.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6248

Affected Products

Wpforo - User Custom Fields
Wpforo Forum