CVE-2026-28557: wpForo Forum < 2.4.16 Privilege Escalation via Role Synchronization Handler
wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment via the wpforosynchroles AJAX handler. Attackers access the usergroups admin page, accessible to any authenticated user, to obtain a nonce, then remap all wpForo usergroups to arbitrary WordPress roles.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28557?
CVE-2026-28557 is classified as a privilege escalation vulnerability.
How do I fix CVE-2026-28557?
To fix CVE-2026-28557, update wpForo Forum to the latest version where the vulnerability is patched.
Who is affected by CVE-2026-28557?
Authenticated users of wpForo Forum 2.4.14 can exploit CVE-2026-28557 to escalate their privileges.
What type of attack does CVE-2026-28557 involve?
CVE-2026-28557 involves a missing capability check that allows bulk usergroup reassignment.
Is there a workaround for CVE-2026-28557?
Currently, no official workaround is provided for CVE-2026-28557, and users should update to the patched version.