CVE-2022-40205: WordPress wpForo Forum plugin <= 2.0.5 - Insecure direct object references (IDOR) vulnerability
Published Nov 8, 2022
·Updated
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved.
Affected Software
1 affected component
gVectors Wpforo Forum Wordpress<=2.0.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress wpForo Forum pluginto a version that resolves this vulnerability.Fixed in 2.0.6
Event History
Nov 8, 2022
CVE Published
via MITRE·06:26 PM
Data Sourced
via MITRE·06:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
CVE-2022-40205
2
What is the title of the vulnerability?
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress.
3
What is the severity of CVE-2022-40205?
The severity of CVE-2022-40205 is medium with a CVSS score of 4.3.
4
How does the vulnerability in wpForo Forum plugin <= 2.0.5 affect users?
The vulnerability allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved.
5
How can I fix the IDOR vulnerability in wpForo Forum plugin <= 2.0.5?
Update to the latest version of wpForo Forum plugin to mitigate the IDOR vulnerability.