CVE-2026-12698: Unknown Wpforo Forum

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.

Affected products

  • Unknown Wpforo Forum: before 3.1.3 (fixed in 3.1.3)

Published 2026-08-04. Last modified 2026-08-26.