wpForo members can alter administrator-controlled account state
wpForo Forum before 3.1.3 does not restrict the profile fields a member may set on their own account. A Subscriber can submit administrator-controlled account-state and reputation fields, allowing a pending or banned account to reactivate itself and permitting arbitrary reputation-score forgery. The public advisory does not disclose the profile endpoint, field names, request parameters or update function.
- Component
- wpForo Forum
- Plugin slug
wpforo-forum- Affected
- < 3.1.3
- Safe version
3.1.3- Published
- Aug 04, 2026
This CVE was published Aug 04, 2026 and is one of 10 known issues for this plugin.
Update, patch or deactivate.
Update wpForo Forum to 3.1.3 or later. Review reactivated, previously banned or unusually high-reputation accounts and restore administrator-controlled profile state from trusted records.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N