An issue exists in the update function in the wpForo Forum plugin prior to 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gvectors wpforo forum |