CVE-2025-66070: WordPress wpForo Forum plugin <= 2.4.10 - Broken Access Control vulnerability
Published Dec 18, 2025
·Updated
Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.10.
Affected Software
1 affected component
WordPress wpForo Forum<=2.4.10
Event History
Dec 18, 2025
CVE Published
via MITRE·07:22 AM
Data Sourced
via MITRE·07:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66070?
CVE-2025-66070 has been classified as a medium severity vulnerability due to its impact on access control mechanisms.
2
How do I fix CVE-2025-66070?
To remediate CVE-2025-66070, upgrade wpForo Forum to version 2.4.11 or later.
3
What effect does CVE-2025-66070 have on wpForo Forum?
CVE-2025-66070 allows attackers to exploit incorrectly configured access control security levels, potentially exposing sensitive information.
4
Who is affected by CVE-2025-66070?
CVE-2025-66070 affects all installations of the wpForo Forum plugin version 2.4.10 and below.
5
When was CVE-2025-66070 disclosed?
CVE-2025-66070 was disclosed on a date that is currently not specified in the available information.