CVE-2026-28559
wpForo Forum 2.4.14 Information Disclosure via Global RSS Feed
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum ID is present in the query.
| CWE | CWE-200 |
| Vendor | gvectors team |
| Product | wpforo forum |
| Published | Feb 28, 2026 |
| Last Updated | Mar 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gvectors team wpforo forum
Be the first to know when new medium vulnerabilities affecting gvectors team wpforo forum are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
gVectors Team / wpForo Forum
2.4 < 2.4.16
References
Credits
Scott Moore - VulnCheck