What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.
Explanation of Vulnerability in Simple Terms
wpForo Forum versions up to 2.0.5 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in forum user, performs unwanted actions on the forum without the user's knowledge. The vulnerability requires user interaction—the victim must visit the attacker's page while authenticated to the forum.
What an attacker can do
Perform unwanted actions on the forum (create posts, modify settings, delete content) on behalf of a logged-in user.
Potential impact on your site
Forum users' accounts can be hijacked to perform actions without their consent, potentially damaging forum integrity and user trust.
Conditions required to exploit
Victim must be logged into wpForo and visit an attacker-controlled webpage.
Key dates
External resources
Related vulnerabilities