CVE-2026-28559Disclosure(gvectors / wpforo_forum)

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum ID is present in the query.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wpforo_forum

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-28); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
wpforo_forum

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2803-01
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28559 - wpForo Forum 2.4.14 Information Disclosure via Global RSS Feed Intel Report: https://ift.tt/KxlJw1I

    Post summary

    A new CVE-2026-28559 affecting wpForo Forum 2.4.14 is disclosed, exposing information via the global RSS feed.

    0000050
    343 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28559 Information Disclosure in wpForo Forum 2.4.14 via Unauthenticated RSS Feed Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28559

    Post summary

    A new information disclosure vulnerability (CVE-2026-28559) affecting wpForo Forum 2.4.14 via an unauthenticated RSS feed endpoint has been reported.

    0000058
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgvectorswpforo_forum-wordpress-

Explore more