CVE-2026-28555

Published
View on NVD ↗
CVSS v3
4.3
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reopen any forum topic via the wpforo_close_ajax handler. Attackers submit a valid nonce with an arbitrary topic ID to bypass the moderator permission requirement and disrupt forum discussions.

<p>wpForo is the first AI powered forum plugin for WordPress. Full-fledged yet easy and light forum solution for your WordPress website. Comes with modern and responsive forum layouts and styles. This WordPress forum plugin brings everything you need to run an efficient and professional community. Powerful and beautiful forum with unique features. The best alternative to bbPress forum plugin.</p> <h4>5 Minute Forum Installation!</h4> <pre><code>1. Activate plugin and find forums on /community/ page, (/community-2/ if /community/ is used), 2. Manage Forum Page, Title, etc in Dashboard &gt; wpForo &gt; Board &gt; Edit Board admin page, 3. Manage Forums in Dashboard &gt; wpForo &gt; Forums admin page, 4. Manage Forum Menu in Dashboard &gt; Appearance &gt; Menu admin page, 5. Manage Forum Widgets in Dashboard &gt; Appearance &gt; Widgets admin page, 6. Manage Forum Colors in Dashboard &gt; wpForo &gt; Settings &gt; Colors &amp; Styles admin page, you can choose forum color styles. </code></pre> <p>Support Forum and Demo: <a href="https://wpforo.com/community/" rel="nofollow ugc">https://wpforo.com/community/</a><br /> Forum Documentation: <a href="https://wpforo.com/docs/wpforo-v3/" rel="nofollow ugc">https://wpforo.com/docs/wpforo-v3/</a><br /> GDPR Compliance: <a href="https://wpforo.com/docs/wpforo-v3/gdpr/" rel="nofollow ugc">https://wpforo.com/docs/wpforo-v3/gdpr/</a></p> <h4>Multi-layout WordPress Forum Plugin</h4> <ol> <li><a href="https://wpforo.com/docs/wpforo-v3/categories-and-forums/forum-layouts/extended-layout/" rel="nofollow ugc"><strong>Extended Forum Layout</strong></a></li> <li><a href="https://wpforo.com/docs/wpforo-v3/categories-and-forums/forum-layouts/simplified-layout/" rel="nofollow ugc"><strong>Simplified Forum Layout</strong></a></li> <li><a href="https://wpforo.com/docs/wpforo-v3/categories-and-forums/forum-layouts/qa-layout/" rel="nofollow ugc"><strong>Question and Answer Forum Layout</strong></a></li> <li><a href="https://wpforo.com/docs/wpforo-v3/categories-and-forums/forum-layouts/threaded-layout/" rel="nofollow ugc"><strong>Threaded Forum Layout</strong></a></li> <li><a href="https://wpforo.com/docs/wpforo-v3/categories-and-forums/forum-layouts/boxed-layout/" rel="nofollow ugc"><strong>Boxed Forum Layout</strong></a></li> </ol> <h4>Migrate to wpForo</h4> <p>Free Migration Tool Go2wpForo: <a href="https://wpforo.com/docs/wpforo-v3/migrate-to-wpforo/" rel="nofollow ugc">https://wpforo.com/docs/wpforo-v3/migrate-to-wpforo/</a></p> <pre><code>- Migrate bbPress forum to wpForo - Migrate Asgaros forum to wpForo - Migrate SimplePress forum to wpForo - Migrate phpBB forum to wpForo - Migrate SMF forum to wpForo - Migrate Joomla Kunena forum to wpForo - Migrate MyBB forum to wpForo </code></pre> <h4>Forum Integration</h4> <p>wpForo forum plugin is well integrated with many Profile Builder and Paid Membership plugins, such as <strong>BuddyPress</strong>, <strong>Ultimate Members</strong>, <strong>WooCommerce Membership</strong>, <strong>Paid Memberships Pro</strong>, <strong>MemberPress</strong>, <strong>Groups</strong> and <strong>SureMembers</strong> plugins.</p> <h4>Forum Translation</h4> <p>wpForo is a WordPress forum plugin with all possibilities of plugin translation. We&#8217;d really appreciate if you could help <a href="https://translate.wordpress.org/projects/wp-plugins/wpforo/" rel="nofollow ugc">translating wpForo forum plugin to your language here</a>.</p> <h4>FORUM FEATURES</h4> <ul> <li>360° AI-Powered Features <ul> <li>AI Semantic Search</li> <li>AI Topic Summarization</li> <li>AI Topic Suggestions</li> <li>AI Multi-Language Translation</li> <li>AI Chat Assistant</li> <li>AI Bot Reply &amp; Suggest Reply</li> <li>AI Content Moderation</li> <li>AI Spam Detection</li> <li>AI Toxic Content Detection</li> <li>AI Tasks — Automated Topic Generation</li> <li>AI Tasks — Automated Reply Generation</li> <li>AI Tasks — Automated Topic Tag Moderation</li> <li>AI Analytics &amp; Insights</li> <li>AI Knowledge Generation (RAG)</li> <li>AI Content Indexing &#8211; Text, Images, Documents</li> </ul> </li> <li>Multi-board: Allows to have multiple separate forum pages</li> <li>Multi-language: Allows to forums with different languages</li> <li>Multi-layout: Four modern forum layouts (Q&amp;A, Threaded&#8230;)</li> <li>Designed for small and extremely large forums/communities.</li> <li>Migrate from other forums using <a href="https://wpforo.com/community/migrate-to-wpforo-from-other-forum-plugins/migrate-to-wpforo-go2wpforo-tool/" rel="nofollow ugc">Go2wpForo</a> tool.</li> <li>Four different forum layouts and designs.</li> <li>Six set of forum color styles including dark style.</li> <li>Super responsive forum on all kind of devices.</li> <li>Live user notification system</li> <li>Built-in forum SEO functions.</li> <li>Built-in forum Sitemap and Search Engine ping.</li> <li>Built-in forum Cache System.</li> <li>Built-in forum Antispam and Akismet integration.</li> <li>Advanced forum user profile system.</li> <li>Forum Member Rating and Badges.</li> <li>Built-in forum/topic subscription.</li> <li>Drag and Drop forum management system.</li> <li>Topic and Post front-end moderation.</li> <li>Forum topics and posts Read / Unread logging.</li> <li>Topic Tags and Tags Widget.</li> <li>Forum styles with different colors.</li> <li>Built-in, powerful forum Usergroup system.</li> <li>Forum Access sets per Usergroup per Forum.</li> <li>Forum Phrase System for quick translation.</li> <li>WordPress .MO/.PO translation files.</li> <li>Tools and options for GDPR Compliance</li> <li>Social Network Share Buttons</li> <li>BuddyPress Integration</li> <li>Ultimate Member Integration</li> </ul> <h4>Need more forum features?</h4> <p>Find wpForo forum plugin addons on <a href="https://gvectors.com/product-category/wpforo/" rel="nofollow ugc">gVectors Team website&#8230;</a></p> <h4>Use of 3rd Party Services</h4> <p>wpForo connects to external services operated by gVectors Team for certain features. These connections are optional and only active when the corresponding features are enabled by the forum administrator.</p> <p><strong>gVectors AI API</strong> (api.gvectors.com, api.gvectors.net)</p> <p>When AI features are enabled by the forum administrator, wpForo sends forum content (topics, posts, and metadata) to the gVectors AI API for processing. This includes:</p> <ul> <li>Content Indexing: Forum content is sent to embedding generation for vector database</li> <li>Semantic Search: Query is sent for embedding for vector search</li> <li>AI Translation: Forum text is sent for translation into other languages</li> <li>AI Summarization: Topic content is sent for automatic summary generation</li> <li>Content Moderation: New posts are sent for AI-powered content analysis</li> <li>AI Chat: Conversation context is sent for AI response generation</li> <li>Topic Suggestions: Forum data is sent for generating related topic recommendations</li> </ul> <p>No data is sent to the AI API unless the forum administrator explicitly enables AI features, accepts the Terms of Service and Privacy Policy, and configures an API key. A fallback domain (api.gvectors.net) may be used automatically if the primary domain is unreachable.</p> <p><a href="https://wpforo.com/wpforo-ai-terms-of-service/" rel="nofollow ugc">Terms of Service</a><br /> <a href="https://wpforo.com/wpforo-ai-privacy-policy/" rel="nofollow ugc">Privacy Policy</a></p> <p><strong>gVectors Addons Store</strong> (gvectors.com)</p> <p>When using wpForo addons purchased from the gVectors store, the plugin communicates with gvectors.com to verify addon licenses and deliver automatic updates through the WordPress Dashboard. This includes sending your site URL and license key to validate your purchase and check for available addon updates.</p> <p><a href="https://gvectors.com/terms-and-conditions/" rel="nofollow ugc">Terms of Service</a><br /> <a href="https://gvectors.com/privacy-policy/" rel="nofollow ugc">Privacy Policy</a></p>
WordPress Plugin DirectoryWordPress Plugin Directory
1.73M