CVE-2022-40206 MEDIUM

CVE-2022-40206: WordPress wpForo Forum plugin <= 2.0.5 - Insecure direct object references (IDOR) vulnerability

Vendor Gvectors Team
Product wpForo Forum (WordPress plugin)
Published November 8, 2022
Last update April 28, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public.

Explanation of Vulnerability in Simple Terms

02Summary

wpForo Forum versions up to 2.0.5 contain a vulnerability allowing authenticated users with low privileges to read sensitive data, modify content, or disrupt site functionality. The flaw requires a valid user account but no special permissions. Site administrators should update to a version newer than 2.0.5 to remediate the issue.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify content, or disrupt site availability with a low-privilege user account.

Potential impact on your site

04Site Impact

Forum data and site functionality may be compromised by any registered user, even those without admin or moderator roles.

Conditions required to exploit

05Prerequisites

Attacker must have a valid user account on the WordPress site with low-level privileges.

Key dates

06Disclosure timeline

November 8, 2022 CVE published
April 28, 2026 Record updated