Vulnerability Bulletins |
CVE-2026-28557 |
|
| Affected software | WORDPRESS |
| wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment via the wpforo_synch_roles AJAX handler. Attackers access the usergroups admin page, accessible to any authenticated user, to obtain a nonce, then remap all wpForo usergroups to arbitrary WordPress roles. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-28557 | |






