Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitieswpForo Forum

wpForo Forum vulnerabilities

wpForo Forum has 39 known vulnerabilities in this database. The most recent published record is dated 25 Sep 2026.

Known vulnerabilities
39
Active installs
20,000+
Latest version
3.2.2
Last updated
28 Sep 2026
Most recent
25 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Security weakness
CVE-2026-80514
Medium 5.3Before 3.1.6Fixed in 3.1.612 d ago
Cross-site scripting (XSS)
CVE-2026-93747
Medium 6.4Up to 3.1.6Fixed in a later version (latest 3.2.2)12 d ago
SQL injection
CVE-2026-80513
High 7.5Before 3.1.6Fixed in 3.1.613 d ago
Broken access control
CVE-2026-91092
Medium 4.3Up to 3.1.5Fixed in a later version (latest 3.2.2)22 Sep 2026
SQL injection
CVE-2026-5097
High 7.5Up to 2.4.17Fixed in a later version (latest 3.2.2)28 Aug 2026
Broken access control
CVE-2026-12698
Medium 4.3Before 3.1.3Fixed in 3.1.34 Aug 2026
Cross-site scripting (XSS)
CVE-2026-12696
Medium 5.4Before 3.1.2Fixed in 3.1.21 Aug 2026
Broken access control
CVE-2026-12697
Medium 5.4Before 3.1.2Fixed in 3.1.231 Jul 2026
Cross-site scripting (XSS)
CVE-2026-15021
Medium 6.4Up to 3.1.1Fixed in a later version (latest 3.2.2)16 Jul 2026
Remote code execution
CVE-2026-6248
High 8.1Up to 3.0.5Fixed in a later version (latest 3.2.2)20 Apr 2026
Broken access control
CVE-2026-4666
Medium 6.5Up to 2.4.16Fixed in a later version (latest 3.2.2)17 Apr 2026
Arbitrary file deletion
CVE-2026-5809
High 7.1Up to 3.0.2Fixed in a later version (latest 3.2.2)11 Apr 2026
Arbitrary file deletion
CVE-2026-3666
High 8.8Up to 2.4.16Fixed in a later version (latest 3.2.2)4 Apr 2026
SQL injection
CVE-2026-28562
High 8.2Before 2.4.15Fixed in 2.4.1528 Feb 2026
Broken access control
CVE-2026-28557
Medium 6.5Before 2.4.16Fixed in 2.4.1628 Feb 2026
SQL injection
CVE-2026-1581
High 7.5Up to 2.4.14Fixed in a later version (latest 3.2.2)19 Feb 2026
PHP object injection
CVE-2026-0910
High 8.8Up to 2.4.13Fixed in a later version (latest 3.2.2)11 Feb 2026
SQL injection
CVE-2025-13126
High 7.5Up to 2.4.12Fixed in a later version (latest 3.2.2)14 Dec 2025
SQL injection
CVE-2025-11740
Medium 6.5Up to 2.4.9Fixed in a later version (latest 3.2.2)1 Nov 2025
SQL injection
CVE-2025-4203
High 7.5Up to 2.4.8Fixed in a later version (latest 3.2.2)25 Oct 2025
Cross-site scripting (XSS)
CVE-2025-4406
Medium 5.4Up to 2.4.5Fixed in a later version (latest 3.2.2)10 Jul 2025
Arbitrary file read
CVE-2025-0764
Medium 6.5Before 2.4.2Fixed in 2.4.228 Feb 2025
SQL injection
CVE-2024-3200
Critical 9.9Before 2.3.4Fixed in 2.3.41 Jun 2024
Cross-site scripting (XSS)
CVE-2023-2309
Medium 6.1Before 2.1.9Fixed in 2.1.924 Jul 2023
Remote code execution
CVE-2023-2249
High 8.8Up to 2.1.7Fixed in a later version (latest 3.2.2)9 Jun 2023
Arbitrary file upload
CVE-2022-40200
Critical 9.9Up to 2.0.9Fixed in a later version (latest 3.2.2)17 Nov 2022
Cross-site request forgery (CSRF)
CVE-2022-40192
High 7.1Up to 2.0.9Fixed in a later version (latest 3.2.2)17 Nov 2022
Cross-site request forgery (CSRF)
CVE-2022-40632
Medium 5.4Up to 2.0.5Fixed in a later version (latest 3.2.2)8 Nov 2022
Broken access control
CVE-2022-40206
Medium 6.3Up to 2.0.5Fixed in a later version (latest 3.2.2)8 Nov 2022
Broken access control
CVE-2022-40205
Medium 5.4Up to 2.0.5Fixed in a later version (latest 3.2.2)8 Nov 2022
Cross-site request forgery (CSRF)
CVE-2022-38144
High 8.8Up to 2.0.5Fixed in a later version (latest 3.2.2)9 Sep 2022
Open redirect
CVE-2021-24406
Medium 6.1Before 1.9.7Fixed in 1.9.76 Jul 2021
Cross-site request forgery (CSRF)
CVE-2019-19109
High 8.8Not yet publishedCheck for an update15 Jun 2020
Cross-site scripting (XSS)
CVE-2019-19110
Medium 4.8Not yet publishedCheck for an update15 Jun 2020
Cross-site scripting (XSS)
CVE-2019-19111
Medium 6.1Not yet publishedCheck for an update15 Jun 2020
Cross-site scripting (XSS)
CVE-2019-19112
Medium 6.1Not yet publishedCheck for an update15 Jun 2020
Security weakness
CVE-2018-16613
Critical 9.8Before 1.5.2Fixed in 1.5.219 Jun 2019
Cross-site scripting (XSS)
CVE-2018-11709
Medium 6.1Before 1.4.12Fixed in 1.4.124 Jun 2018
SQL injection
CVE-2018-11515
Critical 9.8Before 1.4.5Fixed in 1.4.528 May 2018
Read the published descriptions
CVE-2026-80514, 25 Sep 2026
The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to bypass the limit by spoofing the header and exhaust the site owner's metered AI credits. CVE record
CVE-2026-93747, 25 Sep 2026
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output escaping in the profile_update action - the raw $_POST['data'] array is copied into a $custom_fields variable before validate() and sanitize() run, both of which operate only on a parallel $user reference, leaving $custom_fields unsanitized when it is persisted via update_custom_fields(); on render, wpforo_decode() reverses the entity encoding and the value is echoed without escaping in field_wrap_profile(). This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-80513, 24 Sep 2026
The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before 3.1.6 itself; if one is present via another installed wpForo Forum WordPress plugin before 3.1.6 or , this could lead to remote code execution, arbitrary file operations, or SQL injection. This is an incomplete fix of CVE-2026-49769. CVE record
CVE-2026-91092, 22 Sep 2026
The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to take over another guest author's forum post and modify its title, body, author name, and stored owner email address. This requires that guest posting and editing are enabled on the forum, and that the attacker knows the target guest author's email address. CVE record
CVE-2026-5097, 28 Aug 2026
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-12698, 4 Aug 2026
The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score. CVE record
CVE-2026-12696, 1 Aug 2026
The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator. CVE record
CVE-2026-12697, 31 Jul 2026
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user. CVE record
CVE-2026-15021, 16 Jul 2026
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The sanitize_text_field() function applied at input does not encode double quotes, allowing attribute breakout via a payload that escapes the href attribute context and injects event handler attributes. CVE record
CVE-2026-6248, 20 Apr 2026
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom profile fields, allowing authenticated users to store an arbitrary path instead of a legitimate upload path; and the wpforo_fix_upload_dir() sanitization function in ucf_file_delete() only remaps paths that match the expected pattern, and it is passed directly to the unlink() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Note: The vulnerability requires a file custom field, which requires the wpForo - User Custom Fields addon plugin. CVE record
CVE-2026-4666, 17 Apr 2026
The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all versions up to, and including, 2.4.16. The `post_edit` action handler in `Actions.php` passes `$_REQUEST['post']` directly to `Posts::edit()`, which calls `extract($args, EXTR_OVERWRITE)`. An attacker can inject `post[guestposting]=1` to overwrite the local `$guestposting` variable, causing the entire permission check block to be skipped. The nonce check uses a hardcoded `wpforo_verify_form` action shared across all 8 forum templates, so any user who can view any forum page obtains a valid nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit the title, body, name, and email fields of any forum post, including posts in private forums, admin posts, and moderator posts. Content passes through `wpforo_kses()` which strips JavaScript but allows rich HTML. CVE record
CVE-2026-5809, 11 Apr 2026
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied data[*] arrays from $_REQUEST and store them as postmeta without restricting which fields may contain array values. Because 'body' is included in the allowed topic fields list, an attacker can supply data[body][fileurl] with an arbitrary file path (e.g., wp-config.php or an absolute server path). This poisoned fileurl is persisted to the plugin's custom postmeta database table. Subsequently, when the attacker submits wpftcf_delete[]=body on a topic_edit request, the add_file() method retrieves the stored postmeta record, extracts the attacker-controlled fileurl, passes it through wpforo_fix_upload_dir() which only rewrites legitimate wpforo upload paths and returns all other paths unchanged, and then calls wp_delete_file() on the unvalidated path. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files writable by the PHP process on the server, including critical files such as wp-config. CVE record
CVE-2026-3666, 4 Apr 2026
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server by embedding a crafted path traversal string in a forum post body and then deleting the post. CVE record
CVE-2026-28562, 28 Feb 2026
wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. Attackers exploit the wpfob parameter with CASE WHEN payloads to perform blind boolean extraction of credentials from the WordPress database. CVE record
CVE-2026-28557, 28 Feb 2026
wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment via the wpforo_synch_roles AJAX handler. Attackers access the usergroups admin page, accessible to any authenticated user, to obtain a nonce, then remap all wpForo usergroups to arbitrary WordPress roles. CVE record
CVE-2026-1581, 19 Feb 2026
The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-0910, 11 Feb 2026
The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. CVE record
CVE-2025-13126, 14 Dec 2025
The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2025-11740, 1 Nov 2025
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2025-4203, 25 Oct 2025
The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x’s grammar allows a 'PROCEDURE ANALYSE' clause immediately after a LIMIT clause. Unauthenticated attackers controlling 'row_count' can append a stored‐procedure call, enabling error‐based or time‐based blind SQL injection that can be used to extract sensitive information from the database. CVE record
CVE-2025-4406, 10 Jul 2025
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. CVE record
CVE-2025-0764, 28 Feb 2025
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server. CVE record
CVE-2024-3200, 1 Jun 2024
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2023-2309, 24 Jul 2023
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability. CVE record
CVE-2023-2249, 9 Jun 2023
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services. CVE record
CVE-2022-40200, 17 Nov 2022
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. CVE record
CVE-2022-40192, 17 Nov 2022
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. CVE record
CVE-2022-40632, 8 Nov 2022
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion. CVE record
CVE-2022-40206, 8 Nov 2022
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public. CVE record
CVE-2022-40205, 8 Nov 2022
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved. CVE record
CVE-2022-38144, 9 Sep 2022
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress. CVE record
CVE-2021-24406, 6 Jul 2021
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands) CVE record
CVE-2019-19109, 15 Jun 2020
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. CVE record
CVE-2019-19110, 15 Jun 2020
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter. CVE record
CVE-2019-19111, 15 Jun 2020
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter. CVE record
CVE-2019-19112, 15 Jun 2020
The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php. CVE record
CVE-2018-16613, 19 Jun 2019
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction. CVE record
CVE-2018-11709, 4 Jun 2018
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI. CVE record
CVE-2018-11515, 28 May 2018
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. CVE record

What to do if you run wpForo Forum

If you run wpForo Forum, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new wpForo Forum vulnerabilities

Free. We email you when a new vulnerability is published for wpForo Forum, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support