Headline
CVE-2022-40192: WordPress wpForo Forum plugin <= 2.0.9 - Cross-Site Request Forgery (CSRF) vulnerability - Patchstack
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Verified
Fixed
7.1
CVSS 3.1 score High severity
Report
Monitoring Not reported to be exploited
Vulnerable versions
<= 2.0.9
PSID
cc516f9d86dc
Classification
Cross Site Request Forgery (CSRF)
OWASP Top 10
A5: Broken Access Control
Publicly disclosed
2022-11-17
Details
Cross-Site Request Forgery (CSRF) vulnerability discovered by dhakal_ananda (Patchstack Alliance) in WordPress wpForo Forum plugin (versions <= 2.0.9).
Solution
Update the WordPress wpForo Forum plugin to the latest available version (at least 2.1.0).
References