Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-3666

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Apr 04, 2026
Vendor unknown

Description

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server by embedding a crafted path traversal string in a forum post body and then deleting the post.

References