What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6.
Explanation of Vulnerability in Simple Terms
02Summary
wpForo Forum versions up to 2.2.6 contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform actions on behalf of a logged-in user. An attacker can craft a malicious link or page that, when visited by a forum user, triggers unwanted actions such as deleting posts, modifying settings, or banning users. The vulnerability requires user interaction and affects only the availability of forum operations.
What an attacker can do
03Attacker Capabilities
Trick a logged-in forum user into performing unwanted actions like deleting posts or changing forum settings.
Potential impact on your site
04Site Impact
Forum users can be tricked into performing destructive actions without their knowledge, disrupting forum operations.
Conditions required to exploit
05Prerequisites
Attacker needs a logged-in forum user to visit a malicious link or page they control.
Key dates
06Disclosure timeline
November 30, 2023
CVE published
April 28, 2026
Record updated