CVE-2022-40205 MEDIUM

CVE-2022-40205: WordPress wpForo Forum plugin <= 2.0.5 - Insecure direct object references (IDOR) vulnerability

Vendor Gvectors Team
Product wpForo Forum (WordPress plugin)
Published November 8, 2022
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved.

Explanation of Vulnerability in Simple Terms

02Summary

wpForo Forum versions up to 2.0.5 contain a vulnerability allowing authenticated users with low privileges to modify forum data and disrupt service. An attacker with a basic user account can alter content integrity or cause the forum to become unavailable. No public exploit is currently known, but the vulnerability requires only standard user access to trigger.

What an attacker can do

03Attacker Capabilities

Modify forum content or disrupt forum availability with a low-privilege user account.

Potential impact on your site

04Site Impact

Forum posts and data can be altered by regular users; forum availability may be disrupted without admin intervention.

Conditions required to exploit

05Prerequisites

Attacker must have a registered user account on the WordPress site running wpForo.

Key dates

06Disclosure timeline

November 8, 2022 CVE published
April 28, 2026 Record updated