CVE-2026-28554

wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or unapprove any forum post via the wpforo_approve_ajax AJAX handler. Attackers exploit the nonce-only check by submitting a valid nonce with an arbitrary post ID to bypass moderation controls entirely.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*

History

05 Mar 2026, 15:42

Type Values Removed Values Added
References () https://wordpress.org/plugins/wpforo/ - () https://wordpress.org/plugins/wpforo/ - Product
References () https://wordpress.org/plugins/wpforo/#developers - () https://wordpress.org/plugins/wpforo/#developers - Release Notes
References () https://www.vulncheck.com/advisories/wpforo-forum-missing-authorization-via-post-approval-ajax-handler - () https://www.vulncheck.com/advisories/wpforo-forum-missing-authorization-via-post-approval-ajax-handler - Third Party Advisory
CPE cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*
First Time Gvectors
Gvectors wpforo Forum

02 Mar 2026, 20:30

Type Values Removed Values Added
Summary
  • (es) wpForo Forum 2.4.14 contiene una vulnerabilidad de autorización faltante que permite a los suscriptores autenticados aprobar o desaprobar cualquier publicación del foro a través del gestor AJAX wpforo_approve_ajax. Los atacantes explotan la verificación solo de nonce al enviar un nonce válido con un ID de publicación arbitrario para eludir por completo los controles de moderación.

28 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-28 22:16

Updated : 2026-03-05 15:42


NVD link : CVE-2026-28554

Mitre link : CVE-2026-28554

CVE.ORG link : CVE-2026-28554


JSON object : View

Products Affected

gvectors

  • wpforo_forum
CWE
CWE-862

Missing Authorization