📦 Wpforo Forum

by Gvectors

🔍 What is Wpforo Forum?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-3200

CRITICAL CVSS 9.9 Jun 1, 2024

This SQL injection vulnerability in the wpForo Forum WordPress plugin allows authenticated attackers with contributor-level access or higher to inject malicious SQL queries via the 'slug' parameter in...

CVE-2026-28562

HIGH CVSS 8.2 Feb 28, 2026

CVE-2026-28562 is an unauthenticated SQL injection vulnerability in wpForo WordPress plugin versions 2.4.14 and earlier. Attackers can exploit the wpfob parameter to extract sensitive data like WordPr...

CVE-2023-47870

HIGH CVSS 7.1 Nov 30, 2023

This CSRF vulnerability in the wpForo Forum WordPress plugin allows attackers to force all users to log out by tricking authenticated administrators into clicking malicious links. It affects all wpFor...

CVE-2026-28561

MEDIUM CVSS 5.5 Feb 28, 2026

wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability where administrators can inject persistent JavaScript via forum description fields. The malicious code executes when any user v...

CVE-2026-28555

MEDIUM CVSS 4.3 Feb 28, 2026

wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reopen any forum topic via the wpforo_close_ajax handler. Attackers can submit a va...

CVE-2026-28557

MEDIUM CVSS 6.5 Feb 28, 2026

This vulnerability in wpForo Forum allows authenticated users to reassign all forum user groups to arbitrary WordPress roles, enabling privilege escalation. Any WordPress site running the vulnerable w...

CVE-2026-28559

MEDIUM CVSS 5.3 Feb 28, 2026

wpForo Forum 2.4.14 contains an information disclosure vulnerability where unauthenticated attackers can access private and unapproved forum topics through the global RSS feed endpoint. This affects a...

CVE-2025-0764

MEDIUM CVSS 6.5 Feb 28, 2025

The wpForo Forum WordPress plugin has an arbitrary file read vulnerability that allows authenticated attackers with subscriber-level access or higher to read any file on the server. This affects all v...

CVE-2023-47869

MEDIUM CVSS 4.3 Dec 9, 2024

This vulnerability allows attackers to inject malicious scripts into wpForo Forum WordPress plugin pages through improper HTML tag neutralization. It affects all WordPress sites using wpForo Forum ver...