Description
WordPress Plugin wpForo Forum is prone to multiple vulnerabilities, including local file inclusion, server-side request forgery and PHAR deserialization vulnerabilities. Exploiting these issues may allow an attacker to obtain sensitive information, to make the vulnerable server perform port scanning of hosts in internal or external networks, or to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions, granted a POP chain is also present. WordPress Plugin wpForo Forum version 2.1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1.8 or latest
References
https://www.keysight.com/blogs/tech/nwvs/2023/07/05/cve-2023-2249
Related Vulnerabilities
ReviveAdserver URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-22873)
Apache Tomcat WAR file directory traversal vulnerability
MySQL CVE-2022-21625 Vulnerability (CVE-2022-21625)
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2022-23181)