← Volver al buscador de CVEs

CVE-2026-12697

wpForo Forum

Descripción

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.

CVSS 5.4EPSS 0.16999999999999998%Riesgo 0.55
Ver fuente
Publicación
2026-07-31 07:16:23
Versiones afectadas
<3.1.2
Tipo
Aplicación web
Última modificación
2026-07-31 17:16:30
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L