CVE-2026-12698
Received Received - Intake

wpForo Forum Plugin Privilege Escalation via Profile Field Manipulation

Vulnerability report for CVE-2026-12698, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: WPScan

Description

The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpforo forum to 3.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The wpForo Forum WordPress plugin before version 3.1.3 has a vulnerability where users with a subscriber-level account can edit their profile fields without restrictions. This allows them to modify administrator-controlled fields such as account state or reputation, including reactivating a banned account or altering their forum reputation score.

Impact Analysis

This vulnerability could allow unauthorized users to regain access to banned accounts, manipulate their reputation scores, or activate pending accounts. It undermines forum integrity by enabling users to bypass administrative controls and alter critical account attributes.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR by allowing unauthorized users to modify account states or reputations, which may lead to improper data handling or access. For HIPAA, if the plugin handles protected health information, the flaw could enable unauthorized changes to user profiles, compromising data integrity.

Mitigation Strategies

Update the wpForo Forum WordPress plugin to version 3.1.3 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12698. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart