Arbitrary File Deletion Vulnerability in wpForo Forum Plugin by WordPress
CVE-2026-3666
8.8HIGH
What is CVE-2026-3666?
The wpForo Forum plugin for WordPress is susceptible to arbitrary file deletion due to inadequate validation of file names and paths, which allows attackers with subscriber-level access or higher to exploit path traversal sequences. By embedding malicious path strings into forum post bodies, an attacker can delete arbitrary files on the server, thereby posing a significant security risk. This vulnerability affects all versions of the wpForo Forum plugin up to and including 2.4.16.
Affected Version(s)
wpForo Forum 0 <= 2.4.16