What is CVE-2026-12697?
The wpForo Forum WordPress plugin before version 3.1.2 lacks verification that an AI chat conversation belongs to the requesting user before deleting its messages. This allows users with a subscriber-level account to permanently delete the stored AI chat message history of any other user. Immediate update to the latest plugin version is required.
Azərbaycanca: wpForo Forum WordPress plaginində 3.1.2-dən əvvəlki versiyalarda AI çat mesajlarının silinməsi zamanı istifadəçi yoxlaması çatışmazlığı mövcuddur. Bu boşluq 'Subscriber' səviyyəli hesabı olan istənilən şəxsə digər istifadəçilərin bütün AI çat tarixçəsini həmişəlik silməyə imkan verir. Təcili olaraq plaginin ən son versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the wpForo Forum plugin are affected by CVE-2026-12697?
This vulnerability exists in all plugin versions before 3.1.2.
What can an attacker do by exploiting CVE-2026-12697?
Any user with a subscriber-level account can permanently delete the entire AI chat history of other users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.