CVE-2022-40206: WordPress wpForo Forum plugin <= 2.0.5 - Insecure direct object references (IDOR) vulnerability
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wpForo Forum pluginto a version that resolves this vulnerability.Fixed in 2.0.6
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-40206.
What is the title of this vulnerability?
The title of this vulnerability is 'Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress'.
What is the description of this vulnerability?
The description of this vulnerability is that it allows attackers with subscriber or higher user roles to mark any forum post as private/public.
What is the affected software for this vulnerability?
The affected software for this vulnerability is wpForo Forum plugin <= 2.0.5 on WordPress.
How severe is this vulnerability?
This vulnerability has a severity rating of medium with a severity value of 4.3.