On a wpForo forum with guest editing enabled, an attacker could take over someone else's guest post just by knowing their email. The ownership check trusted an unsigned WordPress comment cookie 🍪
cryptocat.me/blog/researc...
cryptocat.me
wpForo Forum Guest Post Takeover via a Forged Ownership Cookie | CVE-2026-91092 | CryptoCat's Blog
How wpForo let anyone who knew a guest author's email rewrite that author's forum post by forging the WordPress comment author cookie, and what the 3.1.6 fix changed.