AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-12698

MEDIUM · CVSS 4.3 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The wpForo Forum plugin for WordPress prior to version 3.1.3 allows users with subscriber-level access to modify restricted profile fields, including account state and reputation scores. This vulnerability could enable malicious users to self-activate pending or banned accounts and manipulate their forum reputation, potentially undermining the integrity of the forum. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-12698
Severity
MEDIUM
CVSS
4.3
EPSS
0.14%
WordPress

Original NVD Description

The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.