Vulnerabilities
CVE-2026-28559 - wpForo Forum 2.4.14 Information Disclosure via Global RSS Feed
CVE ID : CVE-2026-28559 Published : Feb. 28, 2026, 9:47 p.m. | 27 minutes ago Description : wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum ID is present in the query. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Impact:
information disclosure