CVE-2026-28554: wpForo Forum 2.4.14 Missing Authorization via Post Approval AJAX Handler
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or unapprove any forum post via the wpforoapproveajax AJAX handler. Attackers exploit the nonce-only check by submitting a valid nonce with an arbitrary post ID to bypass moderation controls entirely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28554?
CVE-2026-28554 is considered a high-severity vulnerability due to its potential for unauthorized post approvals.
How do I fix CVE-2026-28554?
To fix CVE-2026-28554, upgrade wpForo Forum to the latest version where the authorization checks have been properly implemented.
Who is affected by CVE-2026-28554?
CVE-2026-28554 affects users of wpForo Forum version 2.4.14 who have authenticated subscriber accounts.
What is the nature of the vulnerability in CVE-2026-28554?
CVE-2026-28554 is a missing authorization vulnerability that allows authenticated users to approve or unapprove forum posts without proper permissions.
Can an attacker exploit CVE-2026-28554 without authentication?
No, an attacker must be an authenticated subscriber to exploit CVE-2026-28554.