WordPress Plugin Vulnerabilities
wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass
Description
The plugin does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to bypass the limit by spoofing the header and exhaust the site owner's metered AI credits.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Usama Arshad
Submitter
Usama Arshad
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-22 (about 3 days ago)
Added
2026-09-22 (about 2 days ago)
Last Updated
2026-09-22 (about 2 days ago)