CVE-2026-28559: wpForo Forum 2.4.14 Information Disclosure via Global RSS Feed
wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum ID is present in the query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28559?
CVE-2026-28559 has a medium severity level due to its potential for information disclosure.
How do I fix CVE-2026-28559?
To fix CVE-2026-28559, update wpForo Forum to the latest version where the vulnerability is patched.
Who is affected by CVE-2026-28559?
Users of wpForo Forum version 2.4.14 are affected by CVE-2026-28559.
Can CVE-2026-28559 be exploited remotely?
Yes, CVE-2026-28559 can be exploited remotely as it allows unauthenticated users to access private forum topics.
What type of data is exposed by CVE-2026-28559?
CVE-2026-28559 exposes private and unapproved forum topics via the global RSS feed.