CVE-2026-28557
EUVD-2026-910628.02.2026, 22:16
wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment via the wpforo_synch_roles AJAX handler. Attackers access the usergroups admin page, accessible to any authenticated user, to obtain a nonce, then remap all wpForo usergroups to arbitrary WordPress roles.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gvectors | wpforo_forum | 2.4.0 ≤ 𝑥 < 2.4.16 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration