What the vulnerability does
01Description
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Explanation of Vulnerability in Simple Terms
A privilege escalation vulnerability in wpForo Forum versions up to 2.0.9 allows authenticated users with low privileges to gain full control of the site. An attacker with a basic user account can read, modify, and delete any content, and disable the site entirely. The vulnerability stems from insufficient permission checks on administrative functions.
What an attacker can do
Read, modify, and delete any site content; disable the site; access sensitive data.
Potential impact on your site
Any registered user can take over your forum and site; data breach and downtime risk.
Conditions required to exploit
Attacker must have a low-privilege user account on the WordPress site.
Key dates
External resources