CVE-2026-28559

wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum ID is present in the query.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2026-02-28 22:16

Updated : 2026-03-04 02:47


NVD link : CVE-2026-28559

Mitre link : CVE-2026-28559

CVE.ORG link : CVE-2026-28559


JSON object : View

Products Affected

gvectors

  • wpforo_forum
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo