- Published on
-
Apr 17, 2026
- Research Description
-
The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all versions up to, and including, 2.4.16. The `post_edit` action handler in `Actions.php` passes `$_REQUEST['post']` directly to `Posts::edit()`, which calls `extract($args, EXTR_OVERWRITE)`. An attacker can inject `post[guestposting]=1` to overwrite the local `$guestposting` variable, causing the entire permission check block to be skipped. The nonce check uses a hardcoded `wpforo_verify_form` action shared across all 8 forum templates, so any user who can view any forum page obtains a valid nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit the title, body, name, and email fields of any forum post, including posts in private forums, admin posts, and moderator posts. Content passes through `wpforo_kses()` which strips JavaScript but allows rich HTML.
- Affected versions
-
max 3.0.0.
Plugin Security Certification
Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Get Plugin Security Certificate
| Previous vulnerability researches |
|
wpForo Forum
(CVE-2019-19109)
, Jun 06, 2024
|
|
wpForo Forum
(CVE-2022-40205)
, Jun 06, 2024
|
|
wpForo Forum
(CVE-2021-24406)
, Jun 06, 2024
|
|
wpForo Forum
(CVE-2022-38144)
, Jun 06, 2024
|
|
wpForo Forum
(CVE-2019-19112)
, Jun 06, 2024
|
| New vulnerability |
|
Classified Listing – Classified ads & Business Directory Plugin
(CVE-2026-14183)
, Jul 24, 2026
|
|
AI ChatBot
(CVE-2026-14185)
, Jul 23, 2026
|
|
Academy LMS – eLearning and online course solution for WordPress
(CVE-2026-14184)
, Jul 23, 2026
|
|
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
(CVE-2026-59522)
, Jul 23, 2026
|
|
Tutor LMS Elementor Addons
(CVE-2026-1372)
, Jul 23, 2026
|