Description
WordPress Plugin wpForo Forum is prone to multiple vulnerabilities, including local file inclusion, server-side request forgery and PHAR deserialization vulnerabilities. Exploiting these issues may allow an attacker to obtain sensitive information, to make the vulnerable server perform port scanning of hosts in internal or external networks, or to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions, granted a POP chain is also present. WordPress Plugin wpForo Forum version 2.1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1.8 or latest
References
https://www.keysight.com/blogs/tech/nwvs/2023/07/05/cve-2023-2249
Related Vulnerabilities
WordPress Plugin Social Login Lite For WooCommerce Security Bypass (1.6.0)
WordPress Plugin Advanced Custom Fields (ACF) PHP Object Injection (6.0.7)
WordPress Plugin Adaptive Images for WordPress Multiple Vulnerabilities (0.6.66)
PleskWin Other Vulnerability (CVE-2013-0133)
WordPress Plugin iThemes Security (formerly Better WP Security) Cross-Site Scripting (5.3.4)