Extension WordPress
Vulnérabilités wpForo Forum
Cette page rassemble les failles publiées pour wpForo Forum, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de wpForo Forum
45 fiches
wpForo Forum <= 3.1.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-3.1.1
3.1.2
15/07/2026
wpForo Forum <= 3.0.9 – Authenticated (Contributor+) SQL Injection
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-3.0.9
3.1.0
26/06/2026
wpForo Forum <= 3.1.0 – Missing Authorization
The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.0. This makes it possible for unauthenticated attackers to perform an…
*-3.1.0
3.1.1
04/06/2026
wpForo Forum <= 3.1.0 – Unauthenticated PHP Object Injection
The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known…
*-3.1.0
3.1.1
04/06/2026
wpForo Forum <= 3.0.6 – Missing Authorization
The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-3.0.6
3.0.7
18/05/2026
wpForo Forum <= 3.0.4 – Unauthenticated SQL Injection
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-3.0.4
3.0.5
07/05/2026
wpForo Forum < 3.0.2 – Missing Authorization
The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 3.0.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
[*, 3.0.2)
3.0.2
21/04/2026
wpForo Forum <= 3.0.5 – Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type…
*-3.0.5
3.0.6
20/04/2026
wpForo Forum <= 2.4.16 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Forum Post Modification via 'guestposting' Parameter
The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all versions up to, and including, 2.4.16. The…
*-2.4.16
3.0.0
16/04/2026
wpForo Forum <= 3.0.2 – Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied data[*] arrays…
*-3.0.2
3.0.3
10/04/2026
wpForo Forum <= 2.4.16 – Authenticated (Subscriber+) Arbitrary File Deletion via Post Body
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for…
*-2.4.16
2.4.17
04/04/2026
wpForo Forum <= 2.4.14 – Unauthenticated Time-Based SQL Injection
The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-2.4.14
2.4.15
18/02/2026
wpForo Forum <= 2.4.13 – Authenticated (Subscriber+) PHP Object Injection
The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level…
*-2.4.13
2.4.14
10/02/2026
wpForo Forum <= 2.4.12 – Unauthenticated SQL Injection
The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied parameter and lack of…
*-2.4.12
2.4.13
13/12/2025
wpForo Forum <= 2.4.10 – Missing Authorization
The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.10. This makes it possible for unauthenticated attackers to perform an…
*-2.4.10
2.4.11
18/11/2025
wpForo Forum <= 2.4.9 – Authenticated (Susbscriber+) SQL Injection
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-2.4.9
2.4.10
31/10/2025
wpForo Forum <= 2.4.8 – Unauthenticated SQL Injection via get_members Function
The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The…
*-2.4.8
2.4.9
24/10/2025
wpForo Forum <= 2.4.6 – Authenticated (Subscriber+) Insecure Direct Object Reference
The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with…
*-2.4.6
2.4.7
03/09/2025
wpForo Forum <= 2.4.5 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.4.5
2.4.6
09/07/2025
wpForo Forum <= 2.4.3 – Authenticated (Subscriber+) Privilege Escalation
The wpForo Forum plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges.
*-2.4.3
2.4.4
02/04/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.