Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action.
https://exchange.xforce.ibmcloud.com/vulnerabilities/39878
http://www.securityfocus.com/archive/1/486884/100/0/threaded