← WordPress Vulnerabilities
WordPress security by component

wpForo Forum

wpForo Forum adds discussion forums to WordPress websites with topics, replies, user profiles, and forum management tools.

wpForo Forum (wpforo-forum) is a WordPress plugin with 10 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 9.9.

Plugin slug: wpforo-forum

CVE-2026-12698: wpForo members can alter administrator-controlled account state

wpForo Forum before 3.1.3 does not restrict the profile fields a member may set on their own account. A Subscriber can submit administrator-controlled account-state and reputation fields, allowing a pending or banned account to reactivate itself and permitting arbitrary reputation-score forgery. The public advisory does not disclose the profile endpoint, field names, request parameters or update function.

PublishedAug 04, 2026
Known safe version3.1.3
Published vulnerabilities for wpforo-forum
Safe version
Aug 04, 2026 CVE-2026-12698
wpForo members can alter administrator-controlled account state
wpForo Forum before 3.1.3 does not restrict the profile fields a member may set on their own account. A Subscriber can submit administrator-controlled account-state and reputation fields, allowing a pending or banned account to reactivate itself and permitting arbitrary reputation-score forgery. The public advisory does not disclose the profile endpoint, field names, request parameters or update function.
3.1.3
CVE4.3
NVDPending
Aug 01, 2026 CVE-2026-12696
wpForo profile fields let Subscribers store JavaScript for administrators
wpForo Forum before 3.1.2 places a user profile field into an HTML attribute on the public participant profile page without sufficient sanitization and escaping. A Subscriber-level user can store a crafted value that breaks the attribute context and executes JavaScript for any visitor, including a logged-in Administrator, who views the profile. The record does not disclose the profile field, save action, output template or exact payload encoding.
3.1.2
CVE5.4
NVDPending
Jul 31, 2026 CVE-2026-12697
wpForo Subscribers can delete other users' AI chat histories
wpForo Forum before 3.1.2 deletes AI chat messages without verifying that the selected conversation belongs to the authenticated requester. A Subscriber-level user can supply another user's conversation identifier and permanently delete that conversation's stored AI chat history. The published record does not identify the request route or action, conversation-ID parameter, callback function or deletion function.
3.1.2
CVE5.4
NVDPending
Apr 04, 2026 CVE-2026-3666
wpForo Forum: Filesystem traversal
wpForo Forum is affected by filesystem traversal. Exploitation requires an authenticated subscriber account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 2.4.16. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending
Nov 01, 2025 CVE-2025-11740
wpForo Forum: SQL injection
wpForo Forum is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Feb 28, 2025 CVE-2025-0764
wpForo Forum: Filesystem traversal
wpForo Forum is affected by filesystem traversal. Exploitation requires an authenticated subscriber account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Dec 09, 2024 CVE-2023-47869
wpForo Forum: Cross-site scripting
wpForo Forum is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVD5.4
Jun 01, 2024 CVE-2024-3200
wpForo Forum: SQL injection
wpForo Forum is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.9
NVD6.5
Jul 24, 2023 CVE-2023-2309
wpForo Forum: Cross-site scripting
wpForo Forum is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVEPending
NVD6.1
Jul 06, 2021 CVE-2021-24406
wpForo Forum: An open redirect
wpForo Forum is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVEPending
NVD6.1