216.73.216.226

CVE-2026-28559

· Published 28/02/2026 22:16 · Modified 28/02/2026 22:16

Labels: CVE-2026-28559 2026-02-28CVE-2026-28559CWE-200[email protected]

Essential information

Published
28/02/2026 22:16
Modified
28/02/2026 22:16
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum ID is present in the query.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wpforo / forum cpe:2.3:a:wpforo:forum:2.4.14:*:*:*:*:*:*:*

References