CVE-2026-6248 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: April 20, 2026
wpForo Forum - Arbitrary File Deletion
Overview
wpForo Forum plugin for WordPress <= 3.0.5 contains an arbitrary file deletion vulnerability caused by improper validation of file-type custom profile fields and insufficient path sanitization, letting authenticated users with subscriber-level access delete arbitrary files, exploit requires the User Custom Fields addon plugin.
Severity & Score
Impact
Authenticated users can delete arbitrary files, potentially leading to remote code execution and full server compromise.
Mitigation
Update to the latest version of wpForo Forum plugin and User Custom Fields addon plugin.
References
- https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.16/wpforo/classes/Actions.php#L1418
- https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.16/wpforo/classes/Members.php#L891
- https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.16/wpforo/includes/functions.php#L3187
- https://plugins.trac.wordpress.org/changeset/3509997/wpforo
- https://www.wordfence.com/threat-intel/vulnerabilities/id/79cc102a-6777-41be-a395-8c2eeb6deb73?source=cve
Social Media Activity(2 posts)
š CVE-2026-6248 - High (8.1) The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom pr... š https://www.thehackerwire.com/vulnerability/CVE-2026-6248/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-6248 - High (8.1) The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom pr... š https://www.thehackerwire.com/vulnerability/CVE-2026-6248/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-6248
- Severity
- High
- CVSS Score
- 8.1
- Type
- undefined
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-22
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H