CVE-2026-12698
wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.
| Vendor | unknown |
| Product | wpforo forum |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpforo forum
Be the first to know when new unknown vulnerabilities affecting unknown wpforo forum are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / wpForo Forum
0 < 3.1.3
References
Credits
Yaswanth Reddy Sunkara WPScan