Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.5
wpForo Forum Plugin Allows Unauthenticated Post Editing
CVE-2026-4666
Summary
The wpForo Forum plugin for WordPress has a security flaw that allows anyone to edit any forum post, including private ones, without permission. This is because the plugin doesn't properly check user access. To fix this, update the plugin to the latest version, version 2.4.17 or higher, which should have this issue addressed.
Original title
The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `class...
Original description
The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all versions up to, and including, 2.4.16. The `post_edit` action handler in `Actions.php` passes `$_REQUEST['post']` directly to `Posts::edit()`, which calls `extract($args, EXTR_OVERWRITE)`. An attacker can inject `post[guestposting]=1` to overwrite the local `$guestposting` variable, causing the entire permission check block to be skipped. The nonce check uses a hardcoded `wpforo_verify_form` action shared across all 8 forum templates, so any user who can view any forum page obtains a valid nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit the title, body, name, and email fields of any forum post, including posts in private forums, admin posts, and moderator posts. Content passes through `wpforo_kses()` which strips JavaScript but allows rich HTML.
nvd CVSS3.1
6.5
Vulnerability type
CWE-862
Missing Authorization
- https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.16/classes/Actions.ph...
- https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.16/classes/Posts.php#...
- https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.16/classes/Posts.php#...
- https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.16/includes/functions...
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fwpforo/tags/2.4.16&new_...
- https://ti.wordfence.io/vendors/patch/1885/download
- https://wordpress.org/plugins/wpforo/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/049ffab1-677d-4112-9f1...
Published: 17 Apr 2026 · Updated: 17 Apr 2026 · First seen: 17 Apr 2026