Security Advisory
CVE-2026-12697
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.