๐Ÿ” CVE Alert

CVE-2026-28559

MEDIUM 5.3

wpForo Forum 2.4.14 Information Disclosure via Global RSS Feed

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum ID is present in the query.

CWE CWE-200
Vendor gvectors team
Product wpforo forum
Published Feb 28, 2026
Last Updated Mar 6, 2026
Stay Ahead of the Next One

Get instant alerts for gvectors team wpforo forum

Be the first to know when new medium vulnerabilities affecting gvectors team wpforo forum are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

gVectors Team / wpForo Forum
2.4 < 2.4.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordpress.org: https://wordpress.org/plugins/wpforo/ wordpress.org: https://wordpress.org/plugins/wpforo/#developers vulncheck.com: https://www.vulncheck.com/advisories/wpforo-forum-information-disclosure-via-global-rss-feed

Credits

Scott Moore - VulnCheck