CVE-2026-3666
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Apr 04, 2026
Vendor
unknown
Description
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server by embedding a crafted path traversal string in a forum post body and then deleting the post.