CVE-2022-40200: WordPress wpForo Forum plugin <= 2.0.9 - Auth. Arbitrary File Upload vulnerability
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress wpForo Forum pluginto a version that resolves this vulnerability.Fixed in 2.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40200?
The severity of CVE-2022-40200 is critical, with a severity value of 8.8.
What is the affected software for CVE-2022-40200?
The affected software for CVE-2022-40200 is the wpForo Forum plugin version 2.0.9 on WordPress.
How can I fix the CVE-2022-40200 vulnerability?
To fix the CVE-2022-40200 vulnerability, you should update the wpForo Forum plugin to a version above 2.0.9.
Where can I find more information about the CVE-2022-40200 vulnerability?
You can find more information about the CVE-2022-40200 vulnerability at the following references: [Link1](https://patchstack.com/database/vulnerability/wpforo/wordpress-wpforo-forum-plugin-2-0-9-arbitrary-file-upload-vulnerability?_s_id=cve) and [Link2](https://wordpress.org/plugins/wpforo/#developers).