What is CVE-2026-12698?
The wpForo Forum WordPress plugin before 3.1.3 contains a vulnerability allowing subscriber-level users to modify administrator-controlled account-state and reputation fields on their own profiles via editing, including self-activation. Affected users should immediately update to version 3.1.3 or later to mitigate this issue.
Azərbaycanca: wpForo Forum pluginində (3.1.3-dən əvvəlki versiyalar) zəiflik aşkar edilib. Subscriber səviyyəli istifadəçilər öz profillərini redaktə edərkən admin tərəfindən idarə olunan hesab vəziyyəti və reputasiya sahələrini dəyişdirə bilir, bu da özlərini aktivləşdirməyə imkan verir. Plugin dərhal 3.1.3 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of the wpForo Forum plugin are affected by CVE-2026-12698?
This vulnerability affects versions of the wpForo Forum plugin prior to 3.1.3.
What can a Subscriber-level user do by exploiting CVE-2026-12698?
A subscriber-level user can modify administrator-controlled account-state and reputation fields on their own profile via editing, which allows self-activation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.