WordPress security changelog
MEDIUM CVE-2026-12698 Received

wpForo members can alter administrator-controlled account state

wpForo Forum before 3.1.3 does not restrict the profile fields a member may set on their own account. A Subscriber can submit administrator-controlled account-state and reputation fields, allowing a pending or banned account to reactivate itself and permitting arbitrary reputation-score forgery. The public advisory does not disclose the profile endpoint, field names, request parameters or update function.

CVE / CNA score 4.3 CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score Pending NVD has not published its own CVSS assessment.
Component
wpForo Forum
Plugin slug
wpforo-forum
Affected
< 3.1.3
Safe version
3.1.3
Published
Aug 04, 2026
Weakness
CWE-284 — Improper Access Control

This CVE was published Aug 04, 2026 and is one of 10 known issues for this plugin.

Update, patch or deactivate.

Update wpForo Forum to 3.1.3 or later. Review reactivated, previously banned or unusually high-reputation accounts and restore administrator-controlled profile state from trusted records.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Primary and upstream sources