What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.
Explanation of Vulnerability in Simple Terms
wpForo Forum versions up to 2.3.4 contain an authorization flaw that allows low-privileged users to modify forum content they should not have access to. The vulnerability requires an authenticated account but no user interaction from victims. Integrity of forum data can be compromised, though confidentiality and availability are not affected.
What an attacker can do
Modify forum posts or settings that should be restricted to higher-privileged users.
Potential impact on your site
Forum moderators or admins may find their posts or settings altered by regular members without authorization.
Conditions required to exploit
Attacker must have a low-privilege account on the forum (e.g., regular member).
Key dates
External resources
Related vulnerabilities