CVE-2026-12697

CVE-2026-12697CVE-2026-12697

Description

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.

Scoring

CVSS 5.4 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Last modified2026-07-31
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.