wpForo Forum

Information

Software Type Plugin
Software Slug wpforo (view on wordpress.org)
Software Status Active
Software Author tomdever
Software Website wpforo.com
Software Downloads 1,735,567
Software Active Installs 20,000
Software Record Last Updated July 13, 2026

Showing 1-20 of 44 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
wpForo Forum <= 3.0.9 - Authenticated (Contributor+) SQL Injection Patched CVE-2026-57636 6.5 daroo June 26, 2026
wpForo Forum <= 3.1.0 - Missing Authorization Patched CVE-2026-49767 5.3 Jakub Herman June 4, 2026
wpForo Forum <= 3.1.0 - Unauthenticated PHP Object Injection Patched CVE-2026-49769 8.1 daroo June 4, 2026
wpForo Forum <= 3.0.6 - Missing Authorization Patched CVE-2026-42682 5.3 Tiago Ventura (perses) May 18, 2026
wpForo Forum <= 3.0.4 - Unauthenticated SQL Injection Patched CVE-2026-40798 7.5 Nguyen Ba Khanh May 7, 2026
wpForo Forum < 3.0.2 - Missing Authorization Patched CVE-2026-40767 5.3 Dahmani Toumi (pegaSUS) April 21, 2026
wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path Patched CVE-2026-6248 8.1 0xd4rk5id3, wackydawg April 20, 2026
wpForo Forum <= 2.4.16 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Forum Post Modification via 'guestposting' Parameter Patched CVE-2026-4666 6.5 Jared Reyes April 16, 2026
wpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter Patched CVE-2026-5809 7.1 Leonid Semenenko (lsemenenko) April 10, 2026
wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body Patched CVE-2026-3666 8.8 Webbernaut, Leonid Semenenko (lsemenenko) April 3, 2026
wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection Patched CVE-2026-1581 7.5 Youssef Elouaer February 18, 2026
wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object Injection Patched CVE-2026-0910 8.8 Webbernaut February 10, 2026
wpForo Forum <= 2.4.12 - Unauthenticated SQL Injection Patched CVE-2025-13126 7.5 Muhamad Visat December 13, 2025
wpForo Forum <= 2.4.10 - Missing Authorization Patched CVE-2025-66070 5.3 daroo November 18, 2025
wpForo Forum <= 2.4.9 - Authenticated (Susbscriber+) SQL Injection Patched CVE-2025-11740 6.5 YC_Infosec October 31, 2025
wpForo Forum <= 2.4.8 - Unauthenticated SQL Injection via get_members Function Patched CVE-2025-4203 7.5 mikemyers October 24, 2025
wpForo Forum <= 2.4.6 - Authenticated (Subscriber+) Insecure Direct Object Reference Patched CVE-2025-58597 4.3 Muhammad Zidan Ali Mansur September 3, 2025
wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar Patched CVE-2025-4406 5.4 Muhan Luo July 9, 2025
wpForo Forum <= 2.4.3 - Authenticated (Subscriber+) Privilege Escalation Patched CVE-2025-31420 8.8 Revan Arifio April 2, 2025
wpForo Forum <= 2.4.1 - Authenticated (Subscriber+) Arbitrary File Read in update Patched CVE-2025-0764 6.5 mikemyers February 27, 2025

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation