CyberRota Analysis
AI-GeneratedThe wpForo Forum plugin for WordPress prior to version 3.1.2 is vulnerable to improper access control, allowing subscribers to delete AI chat message histories belonging to other users. This could lead to unauthorized data loss and disruption of user conversations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential abuse.
CVE
CVE-2026-12697
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
WordPress
Original NVD Description
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.