Feed/CVE-2026-12698
CVE-2026-12698MEDIUMCVSS 4.3

CVE-2026-12698

Published Aug 4, 2026·Updated Aug 4, 2026

NVD Description

The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free