Black Friday Deals 40% OFF

Days
Hours
Minutes

Input validation vulnerability in wpForo Forum 2.2.5

The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.2.5. This means that someone who isn’t logged in can use a malicious link to log out other users if they can get them to click on it. This is because of incorrect or missing nonce validation on the logout() function.

Detected in:

wpForo Forum fixed vulnerable versions: >= * <= 2.2.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.