Back to CVE List

CVE-2026-12697

Vulnerability Description

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
wpForo Forum

External References

Discussion (0)

Add Comment

No comments yet. Be the first!