SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-12697

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The wpForo Forum plugin for WordPress prior to version 3.1.2 is vulnerable to improper access control, allowing subscribers to delete AI chat message histories belonging to other users. This could lead to unauthorized data loss and disruption of user conversations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential abuse.

CVE
CVE-2026-12697
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
WordPress

Original NVD Description

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.