Description
WordPress Plugin wpForo Forum is prone to multiple vulnerabilities, including local file inclusion, server-side request forgery and PHAR deserialization vulnerabilities. Exploiting these issues may allow an attacker to obtain sensitive information, to make the vulnerable server perform port scanning of hosts in internal or external networks, or to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions, granted a POP chain is also present. WordPress Plugin wpForo Forum version 2.1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1.8 or latest
References
https://www.keysight.com/blogs/tech/nwvs/2023/07/05/cve-2023-2249
Related Vulnerabilities
WordPress Plugin WP-VR-view-Add Photo Sphere, 360 video to WordPress Cross-Site Scripting (1.6)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3170)
WordPress Plugin Listing, Classified Ads & Business Directory-uListing Arbitrary File Upload (1.2.1)
PHP Other Vulnerability (CVE-2007-4528)
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud SQL Injection (4.10.8)