CVE-2026-28559

wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum ID is present in the query.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*

History

04 Mar 2026, 02:47

Type Values Removed Values Added
CPE cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*
CWE NVD-CWE-noinfo
References () https://wordpress.org/plugins/wpforo/ - () https://wordpress.org/plugins/wpforo/ - Product
References () https://wordpress.org/plugins/wpforo/#developers - () https://wordpress.org/plugins/wpforo/#developers - Release Notes
References () https://www.vulncheck.com/advisories/wpforo-forum-information-disclosure-via-global-rss-feed - () https://www.vulncheck.com/advisories/wpforo-forum-information-disclosure-via-global-rss-feed - Third Party Advisory
First Time Gvectors
Gvectors wpforo Forum

02 Mar 2026, 20:30

Type Values Removed Values Added
Summary
  • (es) wpForo Forum 2.4.14 contiene una vulnerabilidad de revelación de información que permite a usuarios no autenticados recuperar temas de foro privados y no aprobados a través del endpoint global de feed RSS. Los atacantes solicitan el feed RSS sin un parámetro de ID de foro, eludiendo las cláusulas WHERE de privacidad y estado que solo se aplican cuando un ID de foro específico está presente en la consulta.

28 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-28 22:16

Updated : 2026-03-04 02:47


NVD link : CVE-2026-28559

Mitre link : CVE-2026-28559

CVE.ORG link : CVE-2026-28559


JSON object : View

Products Affected

gvectors

  • wpforo_forum
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo