CVE-2022-40632: WordPress wpForo Forum plugin <= 2.0.5 - Cross-Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress wpForo Forum pluginto a version that resolves this vulnerability.Fixed in 2.0.6
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-40632.
What is the title of this vulnerability?
The title of this vulnerability is 'Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.'
What is the severity of CVE-2022-40632?
The severity of CVE-2022-40632 is medium (5.4).
Which software versions are affected by this vulnerability?
The gVectors Team wpForo Forum plugin versions <= 2.0.5 on WordPress are affected by this vulnerability.
How can this vulnerability be exploited?
This vulnerability can be exploited through Cross-Site Request Forgery (CSRF) attacks, leading to topic deletion on the wpForo Forum plugin.