CVE-2026-12697
Vulnerability Description
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
wpForo Forum
Discussion (0)
Add Comment
No comments yet. Be the first!