cleantalk
Vulnerabilities and Security Researches

wpForo Forum, CVE-2026-28557

CVE, Research URL

CVE-2026-28557

Application

wpForo Forum

Published on
Mar 01, 2026
Research Description
wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment via the wpforo_synch_roles AJAX handler. Attackers access the usergroups admin page, accessible to any authenticated user, to obtain a nonce, then remap all wpForo usergroups to arbitrary WordPress roles.
Affected versions
max 2.4.14.
Status
vulnerable