Arbitrary File Deletion Vulnerability in wpForo Forum Plugin by WordPress
CVE-2026-3666
8.8HIGH
What is CVE-2026-3666?
The wpForo Forum plugin for WordPress is susceptible to arbitrary file deletion due to inadequate validation of file names and paths, which allows attackers with subscriber-level access or higher to exploit path traversal sequences. By embedding malicious path strings into forum post bodies, an attacker can delete arbitrary files on the server, thereby posing a significant security risk. This vulnerability affects all versions of the wpForo Forum plugin up to and including 2.4.16.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wpForo Forum 0 <= 2.4.16