CVE-2026-5809 - wpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter
CVE ID :CVE-2026-5809
Published : April 11, 2026, 8:16 a.m. | 7 hours, 57 minutes ago
Description :The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions ...
Related Vulnerabilities
- CVE-2026-5496: Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability HIGH
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-32252: Chartbrew is an open-source web application that can connect directly to databases and APIs and use HIGH
- CVE-2026-35594: Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrad MEDIUM
- CVE-2026-33736: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including MEDIUM
Related Coverage
Threat Actors