← Volver a CVEs
CVE-2026-28559
MEDIUM5.3
Descripcion
wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum ID is present in the query.
Detalles CVE
Puntuacion CVSS v3.15.3
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado2/28/2026
Ultima modificacion3/4/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
gvectors:wpforo_forum
Debilidades (CWE)
CWE-200
Referencias
https://wordpress.org/plugins/wpforo/(disclosure@vulncheck.com)
https://wordpress.org/plugins/wpforo/#developers(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/wpforo-forum-information-disclosure-via-global-rss-feed(disclosure@vulncheck.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.