CVE-2026-3666: Tomdever Wpforo Forum
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server by embedding a crafted path traversal string in a forum post body and then deleting the post.
Affected products
- Tomdever Wpforo Forum: up to and including 2.4.16
Published 2026-04-04. Last modified 2026-07-24.