HomeWordPress vulnerabilitieswpForo Forum
wpForo Forum vulnerabilities
wpForo Forum has 39 known vulnerabilities in this database. The most recent published record is dated 25 Sep 2026.
- Known vulnerabilities
- 39
- Active installs
- 20,000+
- Latest version
- 3.2.2
- Last updated
- 28 Sep 2026
- Most recent
- 25 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Security weakness CVE-2026-80514 | Medium 5.3 | Before 3.1.6 | Fixed in 3.1.6 | 12 d ago |
| Cross-site scripting (XSS) CVE-2026-93747 | Medium 6.4 | Up to 3.1.6 | Fixed in a later version (latest 3.2.2) | 12 d ago |
| SQL injection CVE-2026-80513 | High 7.5 | Before 3.1.6 | Fixed in 3.1.6 | 13 d ago |
| Broken access control CVE-2026-91092 | Medium 4.3 | Up to 3.1.5 | Fixed in a later version (latest 3.2.2) | 22 Sep 2026 |
| SQL injection CVE-2026-5097 | High 7.5 | Up to 2.4.17 | Fixed in a later version (latest 3.2.2) | 28 Aug 2026 |
| Broken access control CVE-2026-12698 | Medium 4.3 | Before 3.1.3 | Fixed in 3.1.3 | 4 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-12696 | Medium 5.4 | Before 3.1.2 | Fixed in 3.1.2 | 1 Aug 2026 |
| Broken access control CVE-2026-12697 | Medium 5.4 | Before 3.1.2 | Fixed in 3.1.2 | 31 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-15021 | Medium 6.4 | Up to 3.1.1 | Fixed in a later version (latest 3.2.2) | 16 Jul 2026 |
| Remote code execution CVE-2026-6248 | High 8.1 | Up to 3.0.5 | Fixed in a later version (latest 3.2.2) | 20 Apr 2026 |
| Broken access control CVE-2026-4666 | Medium 6.5 | Up to 2.4.16 | Fixed in a later version (latest 3.2.2) | 17 Apr 2026 |
| Arbitrary file deletion CVE-2026-5809 | High 7.1 | Up to 3.0.2 | Fixed in a later version (latest 3.2.2) | 11 Apr 2026 |
| Arbitrary file deletion CVE-2026-3666 | High 8.8 | Up to 2.4.16 | Fixed in a later version (latest 3.2.2) | 4 Apr 2026 |
| SQL injection CVE-2026-28562 | High 8.2 | Before 2.4.15 | Fixed in 2.4.15 | 28 Feb 2026 |
| Broken access control CVE-2026-28557 | Medium 6.5 | Before 2.4.16 | Fixed in 2.4.16 | 28 Feb 2026 |
| SQL injection CVE-2026-1581 | High 7.5 | Up to 2.4.14 | Fixed in a later version (latest 3.2.2) | 19 Feb 2026 |
| PHP object injection CVE-2026-0910 | High 8.8 | Up to 2.4.13 | Fixed in a later version (latest 3.2.2) | 11 Feb 2026 |
| SQL injection CVE-2025-13126 | High 7.5 | Up to 2.4.12 | Fixed in a later version (latest 3.2.2) | 14 Dec 2025 |
| SQL injection CVE-2025-11740 | Medium 6.5 | Up to 2.4.9 | Fixed in a later version (latest 3.2.2) | 1 Nov 2025 |
| SQL injection CVE-2025-4203 | High 7.5 | Up to 2.4.8 | Fixed in a later version (latest 3.2.2) | 25 Oct 2025 |
| Cross-site scripting (XSS) CVE-2025-4406 | Medium 5.4 | Up to 2.4.5 | Fixed in a later version (latest 3.2.2) | 10 Jul 2025 |
| Arbitrary file read CVE-2025-0764 | Medium 6.5 | Before 2.4.2 | Fixed in 2.4.2 | 28 Feb 2025 |
| SQL injection CVE-2024-3200 | Critical 9.9 | Before 2.3.4 | Fixed in 2.3.4 | 1 Jun 2024 |
| Cross-site scripting (XSS) CVE-2023-2309 | Medium 6.1 | Before 2.1.9 | Fixed in 2.1.9 | 24 Jul 2023 |
| Remote code execution CVE-2023-2249 | High 8.8 | Up to 2.1.7 | Fixed in a later version (latest 3.2.2) | 9 Jun 2023 |
| Arbitrary file upload CVE-2022-40200 | Critical 9.9 | Up to 2.0.9 | Fixed in a later version (latest 3.2.2) | 17 Nov 2022 |
| Cross-site request forgery (CSRF) CVE-2022-40192 | High 7.1 | Up to 2.0.9 | Fixed in a later version (latest 3.2.2) | 17 Nov 2022 |
| Cross-site request forgery (CSRF) CVE-2022-40632 | Medium 5.4 | Up to 2.0.5 | Fixed in a later version (latest 3.2.2) | 8 Nov 2022 |
| Broken access control CVE-2022-40206 | Medium 6.3 | Up to 2.0.5 | Fixed in a later version (latest 3.2.2) | 8 Nov 2022 |
| Broken access control CVE-2022-40205 | Medium 5.4 | Up to 2.0.5 | Fixed in a later version (latest 3.2.2) | 8 Nov 2022 |
| Cross-site request forgery (CSRF) CVE-2022-38144 | High 8.8 | Up to 2.0.5 | Fixed in a later version (latest 3.2.2) | 9 Sep 2022 |
| Open redirect CVE-2021-24406 | Medium 6.1 | Before 1.9.7 | Fixed in 1.9.7 | 6 Jul 2021 |
| Cross-site request forgery (CSRF) CVE-2019-19109 | High 8.8 | Not yet published | Check for an update | 15 Jun 2020 |
| Cross-site scripting (XSS) CVE-2019-19110 | Medium 4.8 | Not yet published | Check for an update | 15 Jun 2020 |
| Cross-site scripting (XSS) CVE-2019-19111 | Medium 6.1 | Not yet published | Check for an update | 15 Jun 2020 |
| Cross-site scripting (XSS) CVE-2019-19112 | Medium 6.1 | Not yet published | Check for an update | 15 Jun 2020 |
| Security weakness CVE-2018-16613 | Critical 9.8 | Before 1.5.2 | Fixed in 1.5.2 | 19 Jun 2019 |
| Cross-site scripting (XSS) CVE-2018-11709 | Medium 6.1 | Before 1.4.12 | Fixed in 1.4.12 | 4 Jun 2018 |
| SQL injection CVE-2018-11515 | Critical 9.8 | Before 1.4.5 | Fixed in 1.4.5 | 28 May 2018 |
Read the published descriptions
- CVE-2026-80514, 25 Sep 2026
- The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to bypass the limit by spoofing the header and exhaust the site owner's metered AI credits. CVE record
- CVE-2026-93747, 25 Sep 2026
- The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output escaping in the profile_update action - the raw $_POST['data'] array is copied into a $custom_fields variable before validate() and sanitize() run, both of which operate only on a parallel $user reference, leaving $custom_fields unsanitized when it is persisted via update_custom_fields(); on render, wpforo_decode() reverses the entity encoding and the value is echoed without escaping in field_wrap_profile(). This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-80513, 24 Sep 2026
- The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before 3.1.6 itself; if one is present via another installed wpForo Forum WordPress plugin before 3.1.6 or , this could lead to remote code execution, arbitrary file operations, or SQL injection. This is an incomplete fix of CVE-2026-49769. CVE record
- CVE-2026-91092, 22 Sep 2026
- The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to take over another guest author's forum post and modify its title, body, author name, and stored owner email address. This requires that guest posting and editing are enabled on the forum, and that the attacker knows the target guest author's email address. CVE record
- CVE-2026-5097, 28 Aug 2026
- The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-12698, 4 Aug 2026
- The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score. CVE record
- CVE-2026-12696, 1 Aug 2026
- The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator. CVE record
- CVE-2026-12697, 31 Jul 2026
- The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user. CVE record
- CVE-2026-15021, 16 Jul 2026
- The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The sanitize_text_field() function applied at input does not encode double quotes, allowing attribute breakout via a payload that escapes the href attribute context and injects event handler attributes. CVE record
- CVE-2026-6248, 20 Apr 2026
- The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom profile fields, allowing authenticated users to store an arbitrary path instead of a legitimate upload path; and the wpforo_fix_upload_dir() sanitization function in ucf_file_delete() only remaps paths that match the expected pattern, and it is passed directly to the unlink() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Note: The vulnerability requires a file custom field, which requires the wpForo - User Custom Fields addon plugin. CVE record
- CVE-2026-4666, 17 Apr 2026
- The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all versions up to, and including, 2.4.16. The `post_edit` action handler in `Actions.php` passes `$_REQUEST['post']` directly to `Posts::edit()`, which calls `extract($args, EXTR_OVERWRITE)`. An attacker can inject `post[guestposting]=1` to overwrite the local `$guestposting` variable, causing the entire permission check block to be skipped. The nonce check uses a hardcoded `wpforo_verify_form` action shared across all 8 forum templates, so any user who can view any forum page obtains a valid nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit the title, body, name, and email fields of any forum post, including posts in private forums, admin posts, and moderator posts. Content passes through `wpforo_kses()` which strips JavaScript but allows rich HTML. CVE record
- CVE-2026-5809, 11 Apr 2026
- The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied data[*] arrays from $_REQUEST and store them as postmeta without restricting which fields may contain array values. Because 'body' is included in the allowed topic fields list, an attacker can supply data[body][fileurl] with an arbitrary file path (e.g., wp-config.php or an absolute server path). This poisoned fileurl is persisted to the plugin's custom postmeta database table. Subsequently, when the attacker submits wpftcf_delete[]=body on a topic_edit request, the add_file() method retrieves the stored postmeta record, extracts the attacker-controlled fileurl, passes it through wpforo_fix_upload_dir() which only rewrites legitimate wpforo upload paths and returns all other paths unchanged, and then calls wp_delete_file() on the unvalidated path. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files writable by the PHP process on the server, including critical files such as wp-config. CVE record
- CVE-2026-3666, 4 Apr 2026
- The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server by embedding a crafted path traversal string in a forum post body and then deleting the post. CVE record
- CVE-2026-28562, 28 Feb 2026
- wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. Attackers exploit the wpfob parameter with CASE WHEN payloads to perform blind boolean extraction of credentials from the WordPress database. CVE record
- CVE-2026-28557, 28 Feb 2026
- wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment via the wpforo_synch_roles AJAX handler. Attackers access the usergroups admin page, accessible to any authenticated user, to obtain a nonce, then remap all wpForo usergroups to arbitrary WordPress roles. CVE record
- CVE-2026-1581, 19 Feb 2026
- The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-0910, 11 Feb 2026
- The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. CVE record
- CVE-2025-13126, 14 Dec 2025
- The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2025-11740, 1 Nov 2025
- The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2025-4203, 25 Oct 2025
- The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x’s grammar allows a 'PROCEDURE ANALYSE' clause immediately after a LIMIT clause. Unauthenticated attackers controlling 'row_count' can append a stored‐procedure call, enabling error‐based or time‐based blind SQL injection that can be used to extract sensitive information from the database. CVE record
- CVE-2025-4406, 10 Jul 2025
- The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. CVE record
- CVE-2025-0764, 28 Feb 2025
- The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server. CVE record
- CVE-2024-3200, 1 Jun 2024
- The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2023-2309, 24 Jul 2023
- The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability. CVE record
- CVE-2023-2249, 9 Jun 2023
- The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services. CVE record
- CVE-2022-40200, 17 Nov 2022
- Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. CVE record
- CVE-2022-40192, 17 Nov 2022
- Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. CVE record
- CVE-2022-40632, 8 Nov 2022
- Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion. CVE record
- CVE-2022-40206, 8 Nov 2022
- Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public. CVE record
- CVE-2022-40205, 8 Nov 2022
- Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved. CVE record
- CVE-2022-38144, 9 Sep 2022
- Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress. CVE record
- CVE-2021-24406, 6 Jul 2021
- The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands) CVE record
- CVE-2019-19109, 15 Jun 2020
- The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. CVE record
- CVE-2019-19110, 15 Jun 2020
- The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter. CVE record
- CVE-2019-19111, 15 Jun 2020
- The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter. CVE record
- CVE-2019-19112, 15 Jun 2020
- The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php. CVE record
- CVE-2018-16613, 19 Jun 2019
- An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction. CVE record
- CVE-2018-11709, 4 Jun 2018
- wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI. CVE record
- CVE-2018-11515, 28 May 2018
- The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. CVE record
What to do if you run wpForo Forum
If you run wpForo Forum, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new wpForo Forum vulnerabilities
Free. We email you when a new vulnerability is published for wpForo Forum, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.