WordPress Plugin Vulnerabilities

wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass

Description

The plugin does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to bypass the limit by spoofing the header and exhaust the site owner's metered AI credits.

Proof of Concept

Affects Plugins

Fixed in 3.1.6

References

Miscellaneous

Original Researcher
Usama Arshad
Submitter
Usama Arshad
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-22 (about 3 days ago)
Added
2026-09-22 (about 2 days ago)
Last Updated
2026-09-22 (about 2 days ago)

Other