GHSA-7xp3-pmg2-gcq4MediumCVSS 5.3

The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client...

Published
September 25, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to bypass the limit by spoofing the header and exhaust the site owner's metered AI credits.

🔗 References (3)