CVE-2022-40200 CRITICAL

CVE-2022-40200: WordPress wpForo Forum plugin <= 2.0.9 - Auth. Arbitrary File Upload vulnerability

Vendor Gvectors Team
Product wpForo Forum (WordPress plugin)
Published November 17, 2022
Last update April 28, 2026

CVSS base score

9.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

A privilege escalation vulnerability in wpForo Forum versions up to 2.0.9 allows authenticated users with low privileges to gain full control of the site. An attacker with a basic user account can read, modify, and delete any content, and disable the site entirely. The vulnerability stems from insufficient permission checks on administrative functions.

What an attacker can do

03Attacker Capabilities

Read, modify, and delete any site content; disable the site; access sensitive data.

Potential impact on your site

04Site Impact

Any registered user can take over your forum and site; data breach and downtime risk.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the WordPress site.

Key dates

06Disclosure timeline

November 17, 2022 CVE published
April 28, 2026 Record updated