CVE-2026-12698 PUBLISHED

wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment

Assigner: WPScan
Reserved: 19.06.2026 Published: 04.08.2026 Updated: 04.08.2026

The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.

Product Status

Vendor Unknown
Product wpForo Forum
Versions Default: unaffected
  • affected from 0 to 3.1.3 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE