CVE-2026-28556: wpForo Forum 2.4.14 Missing Authorization via Topic Management Form Handlers
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split any forum topic via the topicmove, topicmerge, and topicsplit form action handlers. Attackers with a valid form nonce can reorganize arbitrary forum content without moderator permissions, including relocating topics to private forums.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28556?
CVE-2026-28556 is considered a high severity vulnerability due to its potential impact on forum topic management permissions.
How do I fix CVE-2026-28556?
To fix CVE-2026-28556, update wpForo Forum to the latest version that addresses the missing authorization vulnerability.
Who is affected by CVE-2026-28556?
Authenticated subscribers of wpForo Forum 2.4.14 are affected by CVE-2026-28556.
What actions can be performed by exploiting CVE-2026-28556?
Exploiting CVE-2026-28556 allows an authenticated subscriber to move, merge, or split any forum topic.
How was CVE-2026-28556 discovered?
CVE-2026-28556 was discovered during a security audit of wpForo Forum, identifying missing authorization controls in topic management.