wpForo Forum < 3.0.2 - Missing Authorization
wpForo Forum
Minimum safe version
3.0.6
Update to 3.0.6 or later to address 48 fixable vulnerabilities
CVE-2026-6248
CVE-2026-4666
wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object Injection
wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection
wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body
wpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter
CVE-2026-28554
CVE-2026-28555
CVE-2026-28556
CVE-2026-28557
CVE-2026-28558
CVE-2026-28559
CVE-2026-28560
CVE-2026-28561
wpForo Forum 2.4.14 SQL Injection via Topics ORDER BY Parameter
CVE-2025-66070
CVE-2025-13126
CVE-2025-11740
wpForo Forum <= 2.4.8 - Unauthenticated SQL Injection via get_members Function
CVE-2025-58597
wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar
CVE-2025-31420
WordPress wpForo Forum Plugin <= 2.4.1 is vulnerable to Arbitrary File Download
CVE-2024-43288
CVE-2024-43289
WordPress wpForo Forum Plugin <= 2.3.3 is vulnerable to SQL Injection
CVE-2023-47872
CVE-2023-47868
CVE-2023-47870
CVE-2023-47869
CVE-2022-38055
CVE-2023-2309
WordPress wpForo Forum Plugin <= 2.1.7 is vulnerable to Local File Inclusion
WordPress wpForo Forum Plugin <= 2.0.9 is vulnerable to Other Vulnerability Type
CVE-2022-40192
CVE-2022-40200
CVE-2022-40632
wpForo Forum <= 2.0.5 - Insecure Direct Object Reference to Forum Privacy Change
CVE-2022-40205
CVE-2022-38144
WordPress wpForo Forum plugin <= 1.4.9 - Unauthenticated SQL Injection (SQLi) vulnerability
WordPress wpForo Forum plugin <= 1.4.11 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2018-16613
CVE-2019-19112
CVE-2019-19111
CVE-2019-19110
CVE-2019-19109
CVE-2021-24406