WordPress security by component
wpForo Forum
Plugin description
wpForo Forum adds discussion forums to WordPress websites with topics, replies, user profiles, and forum management tools.
wpForo Forum (wpforo-forum) is a WordPress plugin with 10 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 9.9.
Plugin slug:
wpforo-forumLatest vulnerability
CVE-2026-12698: wpForo members can alter administrator-controlled account state
wpForo Forum before 3.1.3 does not restrict the profile fields a member may set on their own account. A Subscriber can submit administrator-controlled account-state and reputation fields, allowing a pending or banned account to reactivate itself and permitting arbitrary reputation-score forgery. The public advisory does not disclose the profile endpoint, field names, request parameters or update function.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-12698
wpForo members can alter administrator-controlled account state
wpForo Forum before 3.1.3 does not restrict the profile fields a member may set on their own account. A Subscriber can submit administrator-controlled account-state and reputation fields, allowing a pending or banned account to reactivate itself and permitting arbitrary reputation-score forgery. The public advisory does not disclose the profile endpoint, field names, request parameters or update function.
|
3.1.3 |
CVE4.3
NVDPending
|
| Aug 01, 2026 |
CVE-2026-12696
wpForo profile fields let Subscribers store JavaScript for administrators
wpForo Forum before 3.1.2 places a user profile field into an HTML attribute on the public participant profile page without sufficient sanitization and escaping. A Subscriber-level user can store a crafted value that breaks the attribute context and executes JavaScript for any visitor, including a logged-in Administrator, who views the profile. The record does not disclose the profile field, save action, output template or exact payload encoding.
|
3.1.2 |
CVE5.4
NVDPending
|
| Jul 31, 2026 |
CVE-2026-12697
wpForo Subscribers can delete other users' AI chat histories
wpForo Forum before 3.1.2 deletes AI chat messages without verifying that the selected conversation belongs to the authenticated requester. A Subscriber-level user can supply another user's conversation identifier and permanently delete that conversation's stored AI chat history. The published record does not identify the request route or action, conversation-ID parameter, callback function or deletion function.
|
3.1.2 |
CVE5.4
NVDPending
|
| Apr 04, 2026 |
CVE-2026-3666
wpForo Forum: Filesystem traversal
wpForo Forum is affected by filesystem traversal. Exploitation requires an authenticated subscriber account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 2.4.16. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 01, 2025 |
CVE-2025-11740
wpForo Forum: SQL injection
wpForo Forum is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 28, 2025 |
CVE-2025-0764
wpForo Forum: Filesystem traversal
wpForo Forum is affected by filesystem traversal. Exploitation requires an authenticated subscriber account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 09, 2024 |
CVE-2023-47869
wpForo Forum: Cross-site scripting
wpForo Forum is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVD5.4
|
| Jun 01, 2024 |
CVE-2024-3200
wpForo Forum: SQL injection
wpForo Forum is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.9
NVD6.5
|
| Jul 24, 2023 |
CVE-2023-2309
wpForo Forum: Cross-site scripting
wpForo Forum is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jul 06, 2021 |
CVE-2021-24406
wpForo Forum: An open redirect
wpForo Forum is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD6.1
|