CVE-2026-28555: wpForo Forum 2.4.14 Missing Authorization via Topic Close AJAX Handler
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reopen any forum topic via the wpforocloseajax handler. Attackers submit a valid nonce with an arbitrary topic ID to bypass the moderator permission requirement and disrupt forum discussions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28555?
CVE-2026-28555 is classified as a medium severity vulnerability due to its potential impact on forum topic management.
How do I fix CVE-2026-28555?
To fix CVE-2026-28555, update wpForo Forum to the latest version where the authorization checks have been implemented.
Who is affected by CVE-2026-28555?
CVE-2026-28555 affects users of wpForo Forum version 2.4.14 who are authenticated as subscribers.
What does CVE-2026-28555 exploit?
CVE-2026-28555 exploits a missing authorization vulnerability, allowing unauthorized closure or reopening of forum topics.
Is there a patch available for CVE-2026-28555?
Yes, a patch for CVE-2026-28555 can be found in the latest updates of the wpForo Forum plugin.