
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3666 is a path traversal vulnerability in the wpForo Forum plugin for WordPress that allows authenticated attackers to delete arbitrary files on the server. The flaw affects all versions of the plugin up to and including 2.4.16, and was disclosed on April 4, 2026. It carries a CVSS v3.1 base score of 8.8 (High), assigned by Wordfence (GitHub Advisory, Feedly).
The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The vulnerability exists in the plugin's Posts.php class, which fails to validate or sanitize file name/path inputs against path traversal sequences (e.g., ../) before performing file operations. An attacker exploits this by embedding a crafted path traversal string within a forum post body; when the post is subsequently deleted, the plugin processes the malicious path and deletes the targeted arbitrary file on the server. The fix was introduced in version 2.4.17, as evidenced by the changeset diff between Posts.php in versions 2.4.16 and 2.4.17 (GitHub Advisory, WordPress Trac).
Successful exploitation allows any authenticated user with at minimum subscriber-level access to delete arbitrary files anywhere on the server's filesystem, including critical WordPress configuration files (e.g., wp-config.php), application code, or system files. Deletion of wp-config.php can trigger a WordPress reinstallation flow, potentially enabling a full site takeover. The vulnerability has high impact across confidentiality, integrity, and availability, and could result in complete system compromise or service disruption (GitHub Advisory, Feedly).
As of the time of disclosure, no public proof-of-concept exploit code has been identified and there is no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.038% (12th percentile), indicating a low near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low privilege requirement (subscriber-level) significantly lowers the barrier to exploitation on sites with open user registration (GitHub Advisory).
readme.txt file (e.g., https://target.com/wp-content/plugins/wpforo/readme.txt) or using tools like WPScan.../../../../wp-config.php relative to the plugin's file handling directory).Posts.php, which processes the unvalidated path and deletes the targeted file.wp-config.php), or remove security-critical files to facilitate further compromise (GitHub Advisory, WordPress Trac).wp-config.php, .htaccess, or plugin/theme files; file integrity monitoring alerts for deleted files outside the wpForo plugin directory.wp-config.php deletion); sudden loss of plugin or theme functionality consistent with file removal./community/ or custom forum URLs) from accounts with no prior posting history (Feedly).The vulnerability is patched in wpForo Forum version 2.4.17, which introduces proper file name/path validation in Posts.php (WordPress Trac). Site administrators should immediately upgrade the wpForo Forum plugin to version 2.4.17 or later. As interim mitigations: disable open user registration to prevent untrusted users from obtaining subscriber-level accounts; restrict forum post creation and deletion to trusted roles only; implement file integrity monitoring; and consider temporarily disabling the plugin if upgrading is not immediately possible (Feedly, GitHub Advisory).
The vulnerability was assigned and disclosed by Wordfence, a leading WordPress security firm, and published to the GitHub Advisory Database on April 4, 2026 (GitHub Advisory). Brief mentions appeared on security-focused Mastodon accounts including @offseq and @thehackerwire shortly after disclosure, reflecting routine community awareness of the issue. No significant vendor statements beyond the patch release or major media coverage have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."