{"error":0,"message":null,"data":{"name":"wpForo Forum","plugin":"wpforo","link":"https:\/\/wordpress.org\/plugins\/wpforo\/","latest":"1789754700","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"7503865e2fd17f02fd0a38a923d9fa5f40bd9b961e4351e21162d0c3128a52e9","name":"wpForo Forum [wpforo] < 1.9.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24406","name":"CVE-2021-24406","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24406","description":"[en] The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)","date":"2021-07-06"},{"id":"6e1dc97641d3f0561181f966c750fc385243953f","name":"WordPress wpForo Forum plugin <= 1.9.6 - Open Redirect vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-1-9-6-open-redirect-vulnerability","description":"Open Redirect vulnerability discovered by Hosein Vita in WordPress wpForo Forum plugin (versions <= 1.9.6).","date":"2021-06-14"},{"id":"d1b734be318845f3c6becb506af373a92767d646","name":"wpForo Forum <= 1.9.6 - Open Redirect","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-196-open-redirect","description":"The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)","date":"2021-06-14"},{"id":"a9284931-555b-4c96-86a3-09e1040b0388","name":"wpForo Forum &lt; 1.9.7 - Open Redirect","link":"https:\/\/wpscan.com\/vulnerability\/a9284931-555b-4c96-86a3-09e1040b0388","description":"The plugin did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}]}},{"uuid":"ba157c343b74933039b3fe8c73746113f159a0d725cc121d91ced5363b2dd02c","name":"wpForo Forum [wpforo] < 1.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-19109","name":"CVE-2019-19109","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-19109","description":"[en] The wpForo plugin 1.6.5 for WordPress allows wp-admin\/admin.php?page=wpforo-usergroups CSRF.","date":"2020-06-15"},{"id":"bf4db2d7f2962987acc46a6187641ce9ca1d3915","name":"wpForo Forum <= 1.6.5 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-165-cross-site-request-forgery","description":"The wpForo plugin 1.6.5 for WordPress allows wp-admin\/admin.php?page=wpforo-usergroups CSRF.","date":"2020-05-04"},{"id":"af262a52-1719-48b5-a18d-123d7208baf7","name":"wpForo &lt; 1.7.0 - New Users Set as Admin via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/af262a52-1719-48b5-a18d-123d7208baf7","description":"The plugin did not have CSRF in place in a page, allowing attacker to make a logged in admin set all new users as admins directly","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"b37c2412c4c9f25e5e4e9fff21ce35d77c3f519033d61853e2a459dc9070a3f9","name":"wpForo Forum [wpforo] < 1.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-19110","name":"CVE-2019-19110","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-19110","description":"[en] The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin\/admin.php?page=wpforo-phrases s parameter.","date":"2020-06-15"},{"id":"b6827b1f6342553d74dfab4efc1b84d67e3412f4","name":"wpForo Forum <= 1.6.5 - Cross-Site Scripting via s parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-165-cross-site-scripting-via-s-parameter","description":"The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin\/admin.php?page=wpforo-phrases s parameter.","date":"2020-05-04"},{"id":"0971f5c1-d274-497f-958e-60d4d3a40081","name":"wpForo &lt; 1.7.0 - Reflected Cross-Site Scripting (XSS) via s Parameter","link":"https:\/\/wpscan.com\/vulnerability\/0971f5c1-d274-497f-958e-60d4d3a40081","description":"The plugin did not escape, validate or escape the &#039;s&#039; GET parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"b76effc8b359ccb369c04591dee72039d5279fa7f891fe52f97c9d6862ca0e2a","name":"wpForo Forum [wpforo] < 1.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-19111","name":"CVE-2019-19111","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-19111","description":"[en] The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin\/admin.php?page=wpforo-phrases langid parameter.","date":"2020-06-15"},{"id":"bb5d8ddedbb8133df54ddc34100b7d56f51ea22d","name":"wpForo Forum <= 1.6.5 - Cross-Site Scripting via langid parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-165-cross-site-scripting-via-langid-parameter","description":"The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin\/admin.php?page=wpforo-phrases langid parameter.","date":"2020-05-04"},{"id":"405709da-8eb7-4525-9f1e-850e4d291bab","name":"wpForo &lt; 1.7.0 - Reflected Cross-Site Scripting (XSS) via langid Parameter","link":"https:\/\/wpscan.com\/vulnerability\/405709da-8eb7-4525-9f1e-850e4d291bab","description":"The plugin did not escape, validate or escape the &#039;langid&#039; GET parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"b00e212da1d05060ea33a11b7c0dd7dfb0db2e0d9d1dcae8d700eae576fa2ee7","name":"wpForo Forum [wpforo] < 1.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-19112","name":"CVE-2019-19112","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-19112","description":"[en] The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.","date":"2020-06-15"},{"id":"324bfe3752493df5e68a962b83c9da812d371185","name":"wpForo Forum <= 1.6.5 - Cross-Site Scripting via wpf-dw-td-value class","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-165-cross-site-scripting-via-wpf-dw-td-value-class","description":"The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.","date":"2020-05-04"},{"id":"b4bbc558-7eff-493f-897a-e3843d7843d7","name":"wpForo &lt; 1.7.0 - Reflected Cross-Site Scripting (XSS) via User Agent","link":"https:\/\/wpscan.com\/vulnerability\/b4bbc558-7eff-493f-897a-e3843d7843d7","description":"The plugin did not escape, validate or escape the User Agent header before outputting back in the page, leading to a reflected Cross-Site Scripting issue","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"a54ba819e1757bfa309c1ea5fb5cb4667c16b256f08b68dec6e46ed5c694c3b0","name":"wpForo Forum [wpforo] < 1.5.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-16613","name":"CVE-2018-16613","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-16613","description":"[en] An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.","date":"2019-06-19"},{"id":"392667c87c110a8adcc8ea6e78d9b240edecf67c","name":"wpForo < = 1.5.1 - Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-151-privilege-escalation","description":"An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum user is able to escalate privilege to the forum administrator without any form of user interaction.","date":"2018-09-06"},{"id":"39602630-4bdd-4c95-831f-eff8a85a1f09","name":"wpForo &lt; 1.5.2 - Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/39602630-4bdd-4c95-831f-eff8a85a1f09","description":"The wpForo Forum WordPress plugin was affected by a Privilege Escalation security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"}}},{"uuid":"11861bcc1f6d16130552e9780e59a3220e61500b732c4ac35e88a1ef2633cb34","name":"wpForo Forum [wpforo] < 1.4.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-11709","name":"CVE-2018-11709","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-11709","description":"[en] wpforo_get_request_uri in wpf-includes\/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.","date":"2018-06-04"},{"id":"4d1e3dbdfc442432a7d193dd4a14a599d4cf8d4b","name":"WordPress wpForo Forum plugin <= 1.4.11 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-1-4-11-unauthenticated-reflected-cross-site-scripting-xss-vulnerability","description":"Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by Ryan (Dewhurst Security) in WordPress wpForo Forum plugin (versions <= 1.4.11).","date":"2018-06-20"},{"id":"8c3909103134328bff4bea5ce01ba1b94eca7ba8","name":"wpForo Forum < 1.4.12 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-1412-reflected-cross-site-scripting","description":"wpforo_get_request_uri in wpf-includes\/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.","date":"2018-06-01"},{"id":"356cb307-95a5-46ff-9321-fa56d15143cd","name":"wpForo Forum &lt;= 1.4.11 - Unauthenticated Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/356cb307-95a5-46ff-9321-fa56d15143cd","description":"Version 1.4.11, and below, of the wpForo Forum WordPress Plugin were found to be vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability was due to the Plugin using the $_SERVER[&#039;REQUEST_URI&#039;] PHP variable to create a URL string that was later output within HTML without any output encoding.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"b495274b61ac4d6577a5b7b6b249d9c25bd455a619fd054631e599ccb4f14fe5","name":"wpForo Forum [wpforo] < 1.4.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-11515","name":"CVE-2018-11515","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-11515","description":"[en] The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the \/forum\/ wpfo parameter.","date":"2018-05-28"},{"id":"00767105f82d4574796376b3b8644142c4ecd161","name":"WordPress wpForo Forum plugin <= 1.4.9 - Unauthenticated SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-1-4-9-unauthenticated-sql-injection-sqli-vulnerability-1","description":"Unauthenticated SQL Injection (SQLi) vulnerability found by cate4cafe in WordPress wpForo Forum plugin (versions <= 1.4.9).","date":"2018-06-20"},{"id":"9da75e9cbda51fdd1d01f7b7af27ad00a8b689c8","name":"WordPress wpForo Forum plugin <=1.4.9 - Unauthenticated SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/vulnerability\/wpforo\/wordpress-wpforo-forum-plugin-1-4-9-unauthenticated-sql-injection-sqli-vulnerability","description":"Unauthenticated SQL Injection via a search with the \/forum\/ wpfo parameter found by cate4cafe in WordPress wpForo Forum plugin (versions <=1.4.9).","date":"2018-05-30"},{"id":"007a269bb6a907b2f2932d58a852720346e985fc","name":"wpForo Forum <= 1.4.12 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-1412-sql-injection","description":"The wpForo Forum plugin for WordPress is vulnerable to Blind SQL Injection via the \u2018wpfo\u2019 parameter in versions up to, and including, 1.4.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2018-05-27"},{"id":"f3679c75-8e9c-4034-aff5-0df9f0caa489","name":"wpForo Forum &lt;= 1.4.9 - Unauthenticated SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/f3679c75-8e9c-4034-aff5-0df9f0caa489","description":"The wpForo Forum WordPress plugin was affected by an Unauthenticated SQL Injection security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"c463bb41d6127dce27e164843390ac2606ce40775bc5dcd028781076844bc2ad","name":"wpForo Forum [wpforo] < 2.0.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-38144","name":"CVE-2022-38144","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-38144","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.","date":"2022-09-09"},{"id":"02d040e30337b3df8f53026707f42d2d9eb26c78","name":"WordPress wpForo Forum plugin <= 2.0.5 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-0-5-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability was discovered by Brandon Roldan (Patchstack Alliance) in the WordPress wpForo Forum plugin (versions <= 2.0.5).\nUpdate the WordPress wpForo Forum plugin to the latest available version (at least 2.0.6).","date":"2022-09-08"},{"id":"a55c751aad73a67714317d087ee9a15c726f6a9c","name":"wpForo Forum <= 2.0.5 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-205-cross-site-request-forgery","description":"The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to execute that function, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-09-08"},{"id":"c07e5d48-76cf-438e-a6d7-2fb594de66a4","name":"wpForo Forum &lt; 2.0.6 - Cross-Site Request Forgery","link":"https:\/\/wpscan.com\/vulnerability\/c07e5d48-76cf-438e-a6d7-2fb594de66a4","description":"The plugin does not have CSRF check in some places, which could allow attackers to make logged in users perform unwanted actions","date":null}],"impact":{"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"4b67cb9c3b92b88db5dacfe8be52b58776a9830d718b7173c431dd5d02876da2","name":"wpForo Forum [wpforo] < 2.0.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-40205","name":"CVE-2022-40205","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-40205","description":"[en] Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved\/unsolved.","date":"2022-11-08"},{"id":"e0db2312b84c3e7b2f064214e19a1099eac9acb4","name":"WordPress wpForo Forum plugin <= 2.0.5 - Insecure direct object references (IDOR) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-0-5-insecure-direct-object-references-idor-vulnerability-2","description":"Insecure direct object references (IDOR) vulnerability that allows subscriber+ users to mark any forum post as Solved\/Unsolved was discovered by Dhakal Ananda (Patchstack Alliance) in the WordPress wpForo Forum plugin (versions <= 2.0.5).\nUpdate the WordPress wpForo Forum plugin to the latest available version (at least 2.0.6).","date":"2022-09-26"},{"id":"9d5c3aca5a771b76cdc57062cc9b8584e4493577","name":"wpForo Forum <= 2.0.5 - Insecure Direct Object Reference to Forum Status Change","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-205-insecure-direct-object-reference-to-forum-status-change","description":"The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.5. This makes it possible for authenticated attackers, with subscriber-level access or higher, to mark any forum post as solved\/unsolved.","date":"2022-09-26"},{"id":"d1127579-4f9a-4ad2-86fd-5eae6f9c3c7a","name":"wpForo Forum &lt; 2.0.6 - Subscriber+ Forum Post Set as Solved\/Unsolved via IDOR","link":"https:\/\/wpscan.com\/vulnerability\/d1127579-4f9a-4ad2-86fd-5eae6f9c3c7a","description":"The plugin does not ensure that the forum post marked as solved\/unsolved belong to the user making the request, allowing any authenticated users, such as subscriber to mark arbitrary forum post as solved\/unsolved","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d0d77ed3e488800c34ee3c8d355488fe395f11e5b8ae66ab33fcf35703218c1d","name":"wpForo Forum [wpforo] < 2.0.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-40206","name":"CVE-2022-40206","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-40206","description":"[en] Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private\/public.","date":"2022-11-08"},{"id":"2ecbd2cc1e2344522a0c0e5c72f3b8549ed80b7a","name":"WordPress wpForo Forum plugin <= 2.0.5 - Insecure direct object references (IDOR) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-0-5-insecure-direct-object-references-idor-vulnerability","description":"Insecure direct object references (IDOR) vulnerability that allows subscriber+ users to mark any forum post as Private\/Public was discovered by Dhakal Ananda (Patchstack Alliance) in the WordPress wpForo Forum plugin (versions <= 2.0.5).\nUpdate the WordPress wpForo Forum plugin to the latest available version (at least 2.0.6).","date":"2022-09-26"},{"id":"030ce1cd90169ae391b61a06d3b84ecdbc611087","name":"wpForo Forum <= 2.0.5 - Insecure Direct Object Reference to Forum Privacy Change","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-205-insecure-direct-object-reference-to-forum-privacy-change","description":"The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.5. This makes it possible for authenticated attackers, with subscriber-level access or higher, to mark any forum post as private\/public.","date":"2022-11-26"},{"id":"874f9a6d-6a97-4b73-a867-16f60eeaf389","name":"wpForo Forum &lt; 2.0.6 - Subscriber+ Forum Post Set as Private\/Public via IDOR","link":"https:\/\/wpscan.com\/vulnerability\/874f9a6d-6a97-4b73-a867-16f60eeaf389","description":"The plugin does not ensure that the forum post marked as private\/public belong to the user making the request, allowing any authenticated users, such as subscriber to set arbitrary forum post as private\/public","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"6.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"6.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2d10409629a6c230c0433c555ed9caf4083cda9b1739bda8e70ada6f4c228fc2","name":"wpForo Forum [wpforo] < 2.0.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-40632","name":"CVE-2022-40632","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-40632","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.","date":"2022-11-08"},{"id":"627b56c800b8bcf89102f03cf187cb27b2c7c69e","name":"WordPress wpForo Forum plugin <= 2.0.5 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-0-5-cross-site-request-forgery-csrf-vulnerability-2","description":"Cross-Site Request Forgery (CSRF) vulnerability leading to post deletion discovered by Dhakal Ananda (Patchstack Alliance) in WordPress wpForo Forum plugin (versions <= 2.0.5).\nUpdate the WordPress wpForo Forum plugin to the latest available version (at least 2.0.6).","date":"2022-09-26"},{"id":"0cd89c012cc163f7c3ad0c4a4e74001fa511cf4b","name":"wpForo Forum <= 2.0.5 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-205-cross-site-request-forgery-2","description":"The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on various AJAX actions. This makes it possible for unauthenticated attackers to invoke the associated functions (leading to post deletion for example), via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-09-08"},{"id":"a361c032-d8ee-4879-b0ae-a3b6f5ea4096","name":"wpForo Forum &lt; 2.0.6 - Topic Deletion via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/a361c032-d8ee-4879-b0ae-a3b6f5ea4096","description":"The plugin does not have CSRF check when deletion topics, which could allow attackers to make logged in users with the appropriate privilege to perform such action via a CSRF attack","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c5d3005ee0dc1cf4446e271b49bd4ad544b0c217179594ca605b5d191f5d1a33","name":"wpForo Forum [wpforo] < 2.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-40200","name":"CVE-2022-40200","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-40200","description":"[en] Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.","date":"2022-11-17"},{"id":"2bd343c04d2e92a2275e9e668251b84f216fd184","name":"WordPress wpForo Forum plugin <= 2.0.9 - Arbitrary File Upload vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-0-9-arbitrary-file-upload-vulnerability","description":"Arbitrary File Upload vulnerability discovered by Rafie Muhammad aka Yeraisci (Patchstack Alliance) in WordPress wpForo Forum plugin (versions <= 2.0.9).\nUpdate the WordPress wpForo Forum plugin to the latest available version (at least 2.1.0).","date":"2022-11-09"},{"id":"60c6a425f14710e487cdb42a126e2a62e9e02474","name":"wpForo Forum <= 2.0.9 - Authenticated (Subscriber+) Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-209-authenticated-subscriber-arbitrary-file-upload","description":"The wpForo Forum plugin for WordPress is vulnerable to arbitrary file uploads due to missing protections or file validations in versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with minimal permissions, to upload arbitrary files on the affected sites server which may make remote code execution possible.","date":"2022-11-09"},{"id":"d54d5500-e034-4a4b-ab06-af2e84b7554b","name":"wpForo Forum &lt; 2.1.0 - Subscriber+ Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/d54d5500-e034-4a4b-ab06-af2e84b7554b","description":"The plugin does not validate uploaded files, which could allow any authenticated users, such as subscriber to upload arbitrary files such as PHP","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"9.9","severity":"c","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"9.9","severity":"critical","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"57c8a8d034a91b8cfc72b686470d4ed8b79171786f9cc96d2b83bc17a6131f50","name":"wpForo Forum [wpforo] < 2.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-40192","name":"CVE-2022-40192","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-40192","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.","date":"2022-11-17"},{"id":"d361be054edb50a7fecaece088e8f3e6c7030f96","name":"WordPress wpForo Forum plugin <= 2.0.9 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-0-9-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability discovered by dhakal_ananda (Patchstack Alliance) in WordPress wpForo Forum plugin (versions <= 2.0.9).\nUpdate the WordPress wpForo Forum plugin to the latest available version (at least 2.1.0).","date":"2022-11-17"},{"id":"154da30a312bb3efeadbe029ed7ce1c3a3c7587a","name":"wpForo Forum <= 2.0.9 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-209-cross-site-request-forgery","description":"The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the profile_cover_delete function. This makes it possible for unauthenticated attackers to delete forum users, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-11-09"},{"id":"aef43a5c-522a-467e-a3f6-6c0461f41ba3","name":"wpForo Forum &lt; 2.1.0 - Arbitrary User Deletion via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/aef43a5c-522a-467e-a3f6-6c0461f41ba3","description":"The plugin does not have CSRF check when deleting users, which could allow attackers to make logged in admins delete arbitrary users via a CSRF attack","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"h","score":"7.1","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:H","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9b420437b888db224fd8d34e405b0a22e6d726a86b043517601fb5913840ba20","name":"wpForo Forum [wpforo] < 2.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6cbc0ea436899ad7af62480b1902cd3be8d6e72d","name":"WordPress wpForo Forum Plugin <= 2.0.9 is vulnerable to Other Vulnerability Type","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-0-9-auth-html-injection-vulnerability","description":"Update the WordPress wpForo Forum plugin to the latest available version (at least 2.1.0).\nAnanda Dhakal discovered and reported this Other Vulnerability Type vulnerability in WordPress wpForo Forum Plugin.  This vulnerability has been fixed in version 2.1.0.","date":null}],"impact":[]},{"uuid":"f45f56b08b003ab1d90c923e096f1a55ec79731cf9e1bdd4e8b7b284c1a61120","name":"wpForo Forum [wpforo] < 2.1.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2249","name":"CVE-2023-2249","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2249","description":"[en] The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.","date":"2023-06-09"},{"id":"7ede7852b1b89a108ac6cb678c91b230dd54feb5","name":"WordPress  wpForo Forum Plugin  <= 2.1.7 is vulnerable to Local File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-1-7-authenticated-subscriber-local-file-include-server-side-request-forgery-and-phar-deserialization-via-file-get-contents-vulnerability","description":"Update the WordPress wpForo Forum plugin to the latest available version (at least 2.1.8).\nHamed discovered and reported this Local File Inclusion vulnerability in WordPress wpForo Forum Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentially allow complete database takeover depending on the configuration. This vulnerability has been fixed in version 2.1.8.","date":"2023-06-22"},{"id":"23092961b237aeff521ccc3b8b227e20c3461d7b","name":"wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-217-authenticated-subscriber-local-file-include-server-side-request-forgery-and-phar-deserialization-via-file-get-contents","description":"The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.","date":"2023-06-01"},{"id":"c39884c4-04dc-4ec7-8216-c6992697ae33","name":"wpForo Forum &lt; 2.1.8 - Subscriber+ Arbitrary File Read, Author+ PHAR Deserialization, and Subscriber+ Server-Side Request Forgery via file_get_contents","link":"https:\/\/wpscan.com\/vulnerability\/c39884c4-04dc-4ec7-8216-c6992697ae33","description":"The plugin does not validate some user input before passing it to `file_get_contents`. This leads to multiple vulnerabilities, including arbitrary file read, PHAR deserialization, and Server-Side Request Forgery.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-98","name":"Improper Control of Filename for Include\/Require Statement in PHP Program ('PHP Remote File Inclusion')","description":"The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in \"require,\" \"include,\" or similar functions."},{"cwe":"CWE-829","name":"Inclusion of Functionality from Untrusted Control Sphere","description":"The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere."},{"cwe":"CWE-918","name":"Server-Side Request Forgery (SSRF)","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"3fdeb0fcd9a4081ffef399a20e0b47fbdc5bb0a8098fe08d0fefd19802e2eec6","name":"wpForo Forum [wpforo] < 2.1.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2309","name":"CVE-2023-2309","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2309","description":"[en] The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.","date":"2023-07-24"},{"id":"7759ccc7a32840f7494603aa726b2ba24a6526a3","name":"WordPress  wpForo Forum Plugin  < 2.1.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-1-9-reflected-cross-site-scripting-vulnerability","description":"Update the WordPress wpForo Forum plugin to the latest available version (at least 2.1.9).\nAlex Sanford discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress wpForo Forum Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 2.1.9.","date":"2023-07-06"},{"id":"adacc081778bb0b048771e23b50b959963b51e8a","name":"wpForo Forum <= 2.1.8 - Reflected Cross-Site Scripting via 'wpforo_debug'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-218-reflected-cross-site-scripting-via-wpforo-debug","description":"The wpForo Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018wpforo_debug\u2019 function in versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-07-03"},{"id":"1b3f4558-ea41-4749-9aa2-d3971fc9ca0d","name":"wpForo Forum &lt; 2.1.9 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/1b3f4558-ea41-4749-9aa2-d3971fc9ca0d","description":"The plugin does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"33bc25357718d55e2fdead5c8712847f9f808d1dfbba95f4be8e35eb29402f90","name":"wpForo Forum [wpforo] < 2.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-38055","name":"CVE-2022-38055","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-38055","description":"[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Content Spoofing.This issue affects wpForo Forum: from n\/a through 2.0.9.","date":"2024-06-21"},{"id":"b306dda82c6942dc73f0b3d6ed62f6749b961962","name":"wpForo Forum <= 2.0.9 - Authenticated (Subscriber+) HTML Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-209-authenticated-subscriber-html-injection","description":"The wpForo Forum plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 2.0.9. This is due to insufficient escaping and sanitization of user supplied input. This makes it possible for authenticated attackers, with subscriber-level permissions and above to inject HTML content on pages.","date":"2022-12-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ded5bf451ee442002ae7eac7cfec76655135f09924b8a8e795f9d7fd8d47112e","name":"wpForo Forum [wpforo] < 2.2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47869","name":"CVE-2023-47869","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47869","description":"[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This issue affects wpForo Forum: from n\/a through 2.2.5.","date":"2024-12-09"},{"id":"9253c1dad0b1c8f5db6847edff7ffb3c674b4df8","name":"WordPress  wpForo Forum Plugin  <= 2.2.4 is vulnerable to Content Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-plugin-2-2-3-broken-access-control-vulnerability","description":"No patched version is available. No reply from the vendor.\nJesse McNeil discovered and reported this Content Injection vulnerability in WordPress wpForo Forum Plugin. This could allow a malicious actor to inject their own content into pages and posts of your website. This could also be abused to inject phishing pages into your website. This vulnerability has not been known to be fixed yet.","date":"2023-11-20"},{"id":"ce82ce9cc9a177ac733c39a859a830144d34c2f1","name":"wpForo Forum <= 2.2.5 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-225-missing-authorization","description":"The wpForo Forum plugin for WordPress is vulnerable to unauthorized control of data due to a missing capability check on an unknown function in all versions up to, and including, 2.2.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.","date":"2023-11-20"},{"id":"05cbb6f0-d01e-4192-84a7-19ddbd72613f","name":"wpForo Forum &lt; 2.2.6 - Subscriber+ Content Injection","link":"https:\/\/wpscan.com\/vulnerability\/05cbb6f0-d01e-4192-84a7-19ddbd72613f","description":"The plugin does not properly escape user input, allowing any authenticated users, such as Subscriber to inject content","date":null},{"id":"EUVD-2023-51959","name":"EUVD-2023-51959","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2023-51959","description":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This issue affects wpForo Forum: from n\/a through 2.2.5.","date":"2024-12-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"63760304c66a4d8922a6f4c3ec3463d5ddc6ecb156f7ca1cdbaf21e45d16b9d8","name":"wpForo Forum [wpforo] < 2.2.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47870","name":"CVE-2023-47870","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47870","description":"[en] Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n\/a through 2.2.6.","date":"2023-11-30"},{"id":"81f7dd33d6e44ff19063c56beac9901120e4ee63","name":"WordPress  wpForo Forum Plugin  <= 2.2.4 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-plugin-2-2-3-cross-site-request-forgery-csrf-vulnerability","description":"No patched version is available. No reply from the vendor.\nJesse McNeil discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress wpForo Forum Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has not been known to be fixed yet.","date":"2023-11-20"},{"id":"6b92b489e6436afa68c189904edd2343f4d5afac","name":"wpForo Forum <= 2.2.8 - Cross-Site Request Forgery via logout()","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-225-cross-site-request-forgery-via-logout","description":"The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.8. This is due to missing or incorrect nonce validation on the logout() function. This makes it possible for unauthenticated attackers to log out other users via a forged request granted they can trick a site's user into performing an action such as clicking on a link.","date":"2023-11-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:N\/I:N\/A:H","av":"n","ac":"l","pr":"l","ui":"r","s":"u","c":"n","i":"n","a":"h","score":"7.1","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:N\/I:N\/A:H","score":"7.1","severity":"high","av":"network","ac":"low","pr":"low","ui":"required","s":"unchanged","c":"none","i":"none","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"ddc1fa131f238311d562f09f3740d840f8b0c0dbd8c7930a657ab17d4417c47d","name":"wpForo Forum [wpforo] < 2.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47868","name":"CVE-2023-47868","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47868","description":"[en] Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n\/a through 2.2.3.","date":"2024-05-17"},{"id":"2d96c6b8fcb1366043064594b127d2fbd2999045","name":"WordPress  wpForo Forum Plugin  <= 2.2.3 is vulnerable to Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-plugin-2-2-3-privilege-escalation-vulnerability","description":"Update the WordPress wpForo Forum plugin to the latest available version (at least 2.2.4).\nJesse McNeil discovered and reported this Privilege Escalation vulnerability in WordPress wpForo Forum Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website if high privileges are gained. This vulnerability has been fixed in version 2.2.4.","date":"2023-11-20"},{"id":"eace22864d4b9e996f63c557d1651c4bc91e0e5e","name":"wpForo Forum <= 2.2.3 - Unauthenticated Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-223-unauthenticated-privilege-escalation","description":"The wpForo Forum plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.2.3. This is due to incorrect assignment of user permissions during registration. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.","date":"2023-11-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"7.3","severity":"h","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"7.3","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"52661536b64635d99c3ccd4b0f7cb43406555c565e5169b73e9961638c3bb9ac","name":"wpForo Forum [wpforo] < 2.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47872","name":"CVE-2023-47872","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47872","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.This issue affects wpForo Forum: from n\/a through 2.2.3.","date":"2023-11-30"},{"id":"5f67b0c9c64a549bd4dfe8673912ac9123f58248","name":"WordPress  wpForo Forum Plugin  <= 2.2.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-plugin-2-2-3-cross-site-scripting-xss-vulnerability","description":"Update the WordPress wpForo Forum plugin to the latest available version (at least 2.2.4).\nJesse McNeil discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress wpForo Forum Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 2.2.4.","date":"2023-11-20"},{"id":"633e6b7418d406a90b7c4c60307ff7b6ac2a4689","name":"wpForo Forum <= 2.2.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-223-authenticated-subscriber-stored-cross-site-scripting","description":"The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-11-20"},{"id":"2171845d-8d3b-4e51-9e69-8d3a5447192d","name":"wpForo Forum &lt; 2.2.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/2171845d-8d3b-4e51-9e69-8d3a5447192d","description":"The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"fbe40dec29c95ad545735b9493f627fe09fbbe5e973d99aa2c18a5e094a5a34b","name":"wpForo Forum [wpforo] < 2.3.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3200","name":"CVE-2024-3200","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3200","description":"[en] The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2024-06-01"},{"id":"dfc58843583e3886d68d306c6ba47a982bf85587","name":"wpForo Forum <= 2.3.3 - Authenticated (Contributor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-233-authenticated-contributor-sql-injection","description":"The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2024-05-31"},{"id":"5b8b3109f7253bfe07b9dddae966dc7faf2bb678","name":"WordPress wpForo Forum Plugin <= 2.3.3 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-3-3-authenticated-contributor-sql-injection-vulnerability","description":"<p>WordPress wpForo Forum Plugin <= 2.3.3 is vulnerable to SQL Injection<\/p><p>Software: wpForo Forum<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wpforo\/#developers<\/p><p>Affected Version <= 2.3.3<\/p><p>Fixed in version 2.3.4 <\/p>","date":"2024-06-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"0b64391e0954a1d645ab2fcc7c808b51bbac895746751236e98113b588b1e799","name":"wpForo Forum [wpforo] < 2.3.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-43289","name":"CVE-2024-43289","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-43289","description":"[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n\/a through 2.3.4.","date":"2024-08-26"},{"id":"a75221a62c18a54a5350235af4f29d767361d76a","name":"WordPress wpForo Forum Plugin <= 2.3.4 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-3-4-unauthenticated-sensitive-data-exposure-vulnerability","description":"<p>WordPress wpForo Forum Plugin <= 2.3.4 is vulnerable to Sensitive Data Exposure<\/p><p>Software: wpForo Forum<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wpforo\/#developers<\/p><p>Affected Version <= 2.3.4<\/p><p>Fixed in version 2.3.5 <\/p>","date":"2024-08-16"},{"id":"64252025d6dfedd6de6067b2e0718a9a62272836","name":"wpForo Forum <= 2.3.4 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-234-unauthenticated-sensitive-information-exposure","description":"The wpForo Forum plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.4. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2024-08-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a714fa680e39b23373fd6f53450eab232240078d7ccdc5011bf022d90b0a2ae2","name":"wpForo Forum [wpforo] < 2.3.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-43288","name":"CVE-2024-43288","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-43288","description":"[en] Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n\/a through 2.3.4.","date":"2024-08-18"},{"id":"43538ec54b0577bb02b0027b8dbb0f7d4dbd9116","name":"WordPress wpForo Forum Plugin <= 2.3.4 is vulnerable to Insecure Direct Object References (IDOR)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-3-4-insecure-direct-object-references-idor-vulnerability","description":"<p>WordPress wpForo Forum Plugin <= 2.3.4 is vulnerable to Insecure Direct Object References (IDOR)<\/p><p>Software: wpForo Forum<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wpforo\/#developers<\/p><p>Affected Version <= 2.3.4<\/p><p>Fixed in version 2.3.5 <\/p>","date":"2024-08-16"},{"id":"9c408815d7bab07c94f34d711dc86fe098f9c4da","name":"wpForo Forum <= 2.3.4 - Authenticated (Subscriber+) Insecure Direct Object Reference","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-234-authenticated-subscriber-insecure-direct-object-reference","description":"The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.","date":"2024-08-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"n","score":"8.1","severity":"h","exploitable":"2.8","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:N","score":"8.1","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"2.8","impact":"5.2"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ae89866f397c1985f7077e18728c0c426bd9f7d3c747bfe5bbc38a19c699430d","name":"wpForo Forum [wpforo] < 2.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-0764","name":"wpForo Forum <= 2.4.1 - Authenticated (Subscriber+) Arbitrary File Read in update","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-0764","description":"The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.","date":"0000-00-00"},{"id":"57030c52c02598554f45c9a18974f9e7092e1dde","name":"WordPress wpForo Forum Plugin <= 2.4.1 is vulnerable to Arbitrary File Download","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforo\/vulnerability\/wordpress-wpforo-forum-plugin-2-4-1-authenticated-subscriber-arbitrary-file-read-in-update-vulnerability","description":"<p>WordPress wpForo Forum Plugin <= 2.4.1 is vulnerable to Arbitrary File Download<\/p><p>Software: wpForo Forum<\/p><p>Fixed in version 2.4.2 <\/p><p>Affected Version <= 2.4.1<\/p><p>CVE: CVE-2025-0764<\/p>","date":"2025-02-27"},{"id":"4336f2039da3551428eb5d3b0120c14c865ed57b","name":"wpForo Forum <= 2.4.1 - Authenticated (Subscriber+) Arbitrary File Read in update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-241-authenticated-subscriber-arbitrary-file-read-in-update","description":"The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.","date":"2025-02-27"},{"id":"EUVD-2025-5499","name":"EUVD-2025-5499","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-5499","description":"The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.","date":"2025-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"734d84dda03dbf203640c6eb17876a9b218ede8c63314c7288cc98111ffa0dd0","name":"wpForo Forum [wpforo] < 2.4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-31420","name":"CVE-2025-31420","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-31420","description":"[en] Incorrect Privilege Assignment vulnerability in Tomdever wpForo Forum wpforo allows Privilege Escalation.This issue affects wpForo Forum: from n\/a through <= 2.4.2.","date":"2025-04-04"},{"id":"e73a961f6f9a1da8410d8fc3cff723f75e4bdfe8","name":"wpForo Forum <= 2.4.3 - Authenticated (Subscriber+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-243-authenticated-subscriber-privilege-escalation","description":"The wpForo Forum plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.3.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges.","date":"2025-04-02"},{"id":"EUVD-2025-9756","name":"EUVD-2025-9756","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-9756","description":"Incorrect Privilege Assignment vulnerability in Tomdever wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n\/a through 2.4.2.","date":"2025-04-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:H\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"h","a":"l","score":"7.6","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:H\/A:L","score":"7.6","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"high","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-266","name":"Incorrect Privilege Assignment","description":"A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"98e0e3efa0d0212e318545abc2eeed668ef92a36c49d4081282cd45eeaebb19b","name":"wpForo Forum [wpforo] < 2.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4406","name":"wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4406","description":"The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.","date":"0000-00-00"},{"id":"a2916ad1698e178f467918b09c7821d58c8b6531","name":"wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-245-authenticated-subscriber-stored-cross-site-scripting-via-profile-avatar","description":"The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.","date":"2025-07-09"},{"id":"EUVD-2025-20883","name":"EUVD-2025-20883","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-20883","description":"The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.","date":"2025-07-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a96bea1e16276734c10aa5280a686c876d15251377c03838bf2ee288087360a6","name":"wpForo Forum [wpforo] < 2.4.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-58597","name":"CVE-2025-58597","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-58597","description":"[en] Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n\/a through <= 2.4.6.","date":"2025-09-03"},{"id":"03e1d97cbd75d872fdffe38c97a72e148ee5e3ed","name":"wpForo Forum <= 2.4.6 - Authenticated (Subscriber+) Insecure Direct Object Reference","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-246-authenticated-subscriber-insecure-direct-object-reference","description":"The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform unauthorized actions.","date":"2025-09-03"},{"id":"EUVD-2025-26569","name":"EUVD-2025-26569","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-26569","description":"Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n\/a through 2.4.6.","date":"2025-09-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:N\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"n","a":"l","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:N\/A:L","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a7991f36a8b60fa0f48267dcd5dac622739e3a7b7e3c7de1765d55fec99b0474","name":"wpForo Forum [wpforo] < 2.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4203","name":"wpForo Forum <= 2.4.8 - Unauthenticated SQL Injection via get_members Function","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4203","description":"The wpForo Forum plugin for WordPress is vulnerable to error\u2010based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x\u2019s grammar allows a 'PROCEDURE ANALYSE' clause immediately after a LIMIT clause. Unauthenticated attackers controlling 'row_count' can append a stored\u2010procedure call, enabling error\u2010based or time\u2010based blind SQL injection that can be used to extract sensitive information from the database.","date":"0000-00-00"},{"id":"EUVD-2025-35921","name":"EUVD-2025-35921","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-35921","description":"The wpForo Forum plugin for WordPress is vulnerable to error\u2010based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x\u2019s grammar allows a 'PROCEDURE ANALYSE' clause immediately after a LIMIT clause. Unauthenticated attackers controlling 'row_count' can append a stored\u2010procedure call, enabling error\u2010based or time\u2010based blind SQL injection that can be used to extract sensitive information from the database.","date":"2025-10-25"},{"id":"f41c7be6c6d8c7ed873a67dffa0823169cbbb525","name":"wpForo Forum <= 2.4.8 - Unauthenticated SQL Injection via get_members Function","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-248-unauthenticated-sql-injection-via-get-members-function","description":"The wpForo Forum plugin for WordPress is vulnerable to error\u2010based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x\u2019s grammar allows a 'PROCEDURE ANALYSE' clause immediately after a LIMIT clause. Unauthenticated attackers controlling 'row_count' can append a stored\u2010procedure call, enabling error\u2010based or time\u2010based blind SQL injection that can be used to extract sensitive information from the database.","date":"2025-10-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"b6c9e3aa1bed6ea3857077edc0d5c5e3f1d3fac7f6ee553ba1c88c40d23ebf5a","name":"wpForo Forum [wpforo] < 2.4.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-11740","name":"CVE-2025-11740","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-11740","description":"[en] The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-11-01"},{"id":"b632f4edd6f595fe9ecc98034917ad618825ddd2","name":"wpForo Forum <= 2.4.9 - Authenticated (Susbscriber+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-249-authenticated-susbscriber-sql-injection","description":"The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-10-31"},{"id":"EUVD-2025-37420","name":"EUVD-2025-37420","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-37420","description":"The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-11-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"08cca156385a4a0776b5e0fdbf0efdbf1c40913ac00e2a3e7988c44377802245","name":"wpForo Forum [wpforo] < 2.4.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13126","name":"CVE-2025-13126","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13126","description":"[en] The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-12-14"},{"id":"12a6190a437aee39706cd6ea979893cc97d313d1","name":"wpForo Forum <= 2.4.12 - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-2412-unauthenticated-sql-injection","description":"The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-12-13"},{"id":"EUVD-2025-203280","name":"EUVD-2025-203280","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-203280","description":"The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-12-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"1c7445cdfcf55c0e916550f06e007d325d9f08116e5630315026d85ed333dfbc","name":"wpForo Forum [wpforo] < 2.4.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-66070","name":"CVE-2025-66070","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-66070","description":"[en] Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n\/a through <= 2.4.10.","date":"2025-12-18"},{"id":"9176430ae543be372ad4e0a63396d5b8a08c34ab","name":"wpForo Forum <= 2.4.10 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-2410-missing-authorization","description":"The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2025-11-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"15f212c2fd0eec841c39824b0786b2b2262a404352aee199a9774648f9eb183b","name":"wpForo Forum [wpforo] <= 2.4.14 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.14","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-28562","name":"wpForo Forum 2.4.14 SQL Injection via Topics ORDER BY Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28562","description":"wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. Attackers exploit the wpfob parameter with CASE WHEN payloads to perform blind boolean extraction of credentials from the WordPress database.","date":"2026-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e97a592873812e7c6558a919bfbf695e5797a7915c882ce87eeb48c0e3431480","name":"wpForo Forum [wpforo] < 2.4.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-28561","name":"CVE-2026-28561","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28561","description":"[en] wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent JavaScript via forum description fields echoed without output escaping across multiple theme template files. On multisite installations or with a compromised admin account, attackers set a forum description containing HTML event handlers that execute when any user views the forum listing.","date":"2026-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2f2e1ab61532724c6f526b4ae8e849edb03ecee8ba650a33f7ab09bdc4798e88","name":"wpForo Forum [wpforo] < 2.4.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-28560","name":"CVE-2026-28560","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28560","description":"[en] wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows script injection via forum URL data output into an inline script block using json_encode without the JSON_HEX_TAG flag. Attackers set a forum slug containing a closing script tag or unescaped single quote to break out of the JavaScript string context and execute arbitrary script in all visitors' browsers.","date":"2026-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c4ddd4531b0510d3384573ecda80fa0babaae77096ad038c9b95659f16763904","name":"wpForo Forum [wpforo] < 2.4.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-28559","name":"CVE-2026-28559","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28559","description":"[en] wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum ID is present in the query.","date":"2026-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"dba7809fe934ae7391f9de6e84e238538a8cd21807e7a61b53742dacbfb94c64","name":"wpForo Forum [wpforo] < 2.4.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-28558","name":"CVE-2026-28558","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28558","description":"[en] wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user who views the attacker's profile page.","date":"2026-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"77053d184633b56cbd47597756473ba33a157fe58d1eaa8885f2b1a0944a2c2c","name":"wpForo Forum [wpforo] < 2.4.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-28557","name":"CVE-2026-28557","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28557","description":"[en] wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment via the wpforo_synch_roles AJAX handler. Attackers access the usergroups admin page, accessible to any authenticated user, to obtain a nonce, then remap all wpForo usergroups to arbitrary WordPress roles.","date":"2026-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"ddd58c282f38ed64311e919b62b2e70edff6ee524193eae07a70cda3afe02a9c","name":"wpForo Forum [wpforo] < 2.4.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-28556","name":"CVE-2026-28556","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28556","description":"[en] wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split any forum topic via the topic_move, topic_merge, and topic_split form action handlers. Attackers with a valid form nonce can reorganize arbitrary forum content without moderator permissions, including relocating topics to private forums.","date":"2026-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"aadf4ae0caa2d62658ad3826af79f89c127da85a1042145c2c59268b0f5ade26","name":"wpForo Forum [wpforo] < 2.4.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-28555","name":"CVE-2026-28555","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28555","description":"[en] wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reopen any forum topic via the wpforo_close_ajax handler. Attackers submit a valid nonce with an arbitrary topic ID to bypass the moderator permission requirement and disrupt forum discussions.","date":"2026-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"023dedbd24ba3e9cc4d8b3e5d05cce33462a057700c7425a0bf7cef38b9c3929","name":"wpForo Forum [wpforo] < 2.4.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-28554","name":"CVE-2026-28554","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28554","description":"[en] wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or unapprove any forum post via the wpforo_approve_ajax AJAX handler. Attackers exploit the nonce-only check by submitting a valid nonce with an arbitrary post ID to bypass moderation controls entirely.","date":"2026-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"cffb524ed76af5bee4945e5e493221f78bf47ea2e1f8b92df505fd7bf75ebbc3","name":"wpForo Forum [wpforo] < 3.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5809","name":"wpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5809","description":"The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied data[*] arrays from $_REQUEST and store them as postmeta without restricting which fields may contain array values. Because 'body' is included in the allowed topic fields list, an attacker can supply data[body][fileurl] with an arbitrary file path (e.g., wp-config.php or an absolute server path). This poisoned fileurl is persisted to the plugin's custom postmeta database table. Subsequently, when the attacker submits wpftcf_delete[]=body on a topic_edit request, the add_file() method retrieves the stored postmeta record, extracts the attacker-controlled fileurl, passes it through wpforo_fix_upload_dir() which only rewrites legitimate wpforo upload paths and returns all other paths unchanged, and then calls wp_delete_file() on the unvalidated path. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files writable by the PHP process on the server, including critical files such as wp-config.","date":"0000-00-00"},{"id":"717348dfc81a9bc68320ba455e5cd98b0f080cb3","name":"wpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-302-authenticated-subscriber-arbitrary-file-deletion-via-databodyfileurl-parameter","description":"The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied data[*] arrays from $_REQUEST and store them as postmeta without restricting which fields may contain array values. Because 'body' is included in the allowed topic fields list, an attacker can supply data[body][fileurl] with an arbitrary file path (e.g., wp-config.php or an absolute server path). This poisoned fileurl is persisted to the plugin's custom postmeta database table. Subsequently, when the attacker submits wpftcf_delete[]=body on a topic_edit request, the add_file() method retrieves the stored postmeta record, extracts the attacker-controlled fileurl, passes it through wpforo_fix_upload_dir() which only rewrites legitimate wpforo upload paths and returns all other paths unchanged, and then calls wp_delete_file() on the unvalidated path. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files writable by the PHP process on the server, including critical files such as wp-config.","date":"2026-04-10"},{"id":"EUVD-2026-21676","name":"EUVD-2026-21676","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-21676","description":"The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied data[*] arrays from $_REQUEST and store them as postmeta without restricting which fields may contain array values. Because 'body' is included in the allowed topic fields list, an attacker can supply data[body][fileurl] with an arbitrary file path (e.g., wp-config.php or an absolute server path). This poisoned fileurl is persisted to the plugin's custom postmeta database table. Subsequently, when the attacker submits wpftcf_delete[]=body on a topic_edit request, the add_file() method retrieves the stored postmeta record, extracts the attacker-controlled fileurl, passes it through wpforo_fix_upload_dir() which only rewrites legitimate wpforo upload paths and returns all other paths unchanged, and then calls wp_delete_file() on the unvalidated path. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files writable by the PHP process on the server, including critical files such as wp-config.","date":"2026-04-11"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:H","score":"7.1","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"high","exploitable":null,"impact":null}}},{"uuid":"a1c9e2c7be69eefcd80e160c2e43454cae59083174c82248023ff9d28b248b69","name":"wpForo Forum [wpforo] < 2.4.17","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.17","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3666","name":"wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3666","description":"The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name\/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server by embedding a crafted path traversal string in a forum post body and then deleting the post.","date":"0000-00-00"},{"id":"644f3efd77728e5ce63577ab105db80a94013911","name":"wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-2416-authenticated-subscriber-arbitrary-file-deletion-via-post-body","description":"The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name\/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server by embedding a crafted path traversal string in a forum post body and then deleting the post.","date":"2026-04-03"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"48f841dc8bea0aae476f75813eeac50b50c8a47b3244f53f605f67a68ceda4d0","name":"wpForo Forum [wpforo] < 2.4.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1581","name":"wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1581","description":"The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"0000-00-00"},{"id":"f4aa57a7467b989d405b8092e18a5d5cb3481ad9","name":"wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-2414-unauthenticated-time-based-sql-injection","description":"The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-02-18"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3adcd213b77176bea73958997c0fb220009f7d88dbfc68026b3ca88b89f87162","name":"wpForo Forum [wpforo] < 2.4.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-0910","name":"wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object Injection","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-0910","description":"The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.","date":"0000-00-00"},{"id":"71288838e412fa58bf5098b7432118dbe488252e","name":"wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-2413-authenticated-subscriber-php-object-injection","description":"The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.","date":"2026-02-10"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"4f4e862a6fc4fe3410890873de8f7ccf6508b51e04224a6c4976aed58bdbfd88","name":"wpForo Forum [wpforo] < 3.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4666","name":"CVE-2026-4666","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4666","description":"[en] The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes\/Posts.php` in all versions up to, and including, 2.4.16. The `post_edit` action handler in `Actions.php` passes `$_REQUEST['post']` directly to `Posts::edit()`, which calls `extract($args, EXTR_OVERWRITE)`. An attacker can inject `post[guestposting]=1` to overwrite the local `$guestposting` variable, causing the entire permission check block to be skipped. The nonce check uses a hardcoded `wpforo_verify_form` action shared across all 8 forum templates, so any user who can view any forum page obtains a valid nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit the title, body, name, and email fields of any forum post, including posts in private forums, admin posts, and moderator posts. Content passes through `wpforo_kses()` which strips JavaScript but allows rich HTML.","date":"2026-04-17"},{"id":"cbff54b793e0e15c3e190ed8dae5fe3253c95704","name":"wpForo Forum <= 2.4.16 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Forum Post Modification via 'guestposting' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-2416-missing-authorization-to-authenticated-subscriber-arbitrary-forum-post-modification-via-guestposting-parameter","description":"The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes\/Posts.php` in all versions up to, and including, 2.4.16. The `post_edit` action handler in `Actions.php` passes `$_REQUEST['post']` directly to `Posts::edit()`, which calls `extract($args, EXTR_OVERWRITE)`. An attacker can inject `post[guestposting]=1` to overwrite the local `$guestposting` variable, causing the entire permission check block to be skipped. The nonce check uses a hardcoded `wpforo_verify_form` action shared across all 8 forum templates, so any user who can view any forum page obtains a valid nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit the title, body, name, and email fields of any forum post, including posts in private forums, admin posts, and moderator posts. Content passes through `wpforo_kses()` which strips JavaScript but allows rich HTML.","date":"2026-04-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"22d971902b237e82767fb6fb9e3532955a795278ada0a675ab2308e8c18992a4","name":"wpForo Forum [wpforo] < 3.0.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6248","name":"CVE-2026-6248","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6248","description":"[en] The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom profile fields, allowing authenticated users to store an arbitrary path instead of a legitimate upload path; and the wpforo_fix_upload_dir() sanitization function in ucf_file_delete() only remaps paths that match the expected pattern, and it is passed directly to the unlink() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Note: The vulnerability requires a file custom field, which requires the wpForo - User Custom Fields addon plugin.","date":"2026-04-20"},{"id":"06883f96fe69dc9b5776cc11ab81163a170a6bfe","name":"wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-305-authenticated-subscriber-arbitrary-file-deletion-via-custom-profile-field-file-path","description":"The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom profile fields, allowing authenticated users to store an arbitrary path instead of a legitimate upload path; and the wpforo_fix_upload_dir() sanitization function in ucf_file_delete() only remaps paths that match the expected pattern, and it is passed directly to the unlink() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Note: The vulnerability requires a file custom field, which requires the wpForo - User Custom Fields addon plugin.","date":"2026-04-20"},{"id":"EUVD-2026-23935","name":"EUVD-2026-23935","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-23935","description":"The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom profile fields, allowing authenticated users to store an arbitrary path instead of a legitimate upload path; and the wpforo_fix_upload_dir() sanitization function in ucf_file_delete() only remaps paths that match the expected pattern, and it is passed directly to the unlink() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Note: The vulnerability requires a file custom field, which requires the wpForo - User Custom Fields addon plugin.","date":"2026-04-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"08a76eecf863de68aa0b3bbc285f23f0977f24eb145084e7b854f913c3aaffb6","name":"wpForo Forum [wpforo] < 3.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-40767","name":"CVE-2026-40767","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40767","description":"[en] Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.","date":"2026-06-15"},{"id":"6f25094466d7f6925ef31637c5a5f1b5481cba5c","name":"wpForo Forum < 3.0.2 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-302-missing-authorization","description":"The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 3.0.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-04-21"},{"id":"EUVD-2026-36977","name":"EUVD-2026-36977","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-36977","description":"Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.","date":"2026-06-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-281","name":"Improper Preservation of Permissions","description":"The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"845f15f527a019afd29fde0379b4f87a08aea14f9f11e633007428b462e9ca8e","name":"wpForo Forum [wpforo] < 3.0.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-40798","name":"CVE-2026-40798","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40798","description":"[en] Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.","date":"2026-06-15"},{"id":"1e810585825b3bf75064b2c567b8b35f9597c712","name":"wpForo Forum <= 3.0.4 - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-304-unauthenticated-sql-injection","description":"The wpForo Forum plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-05-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"9.3","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"9.3","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5dd64d778c85a135e009d1e9b0b538b742884abcb06cc29e09823e8f648563f1","name":"wpForo Forum [wpforo] < 3.0.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-42682","name":"CVE-2026-42682","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-42682","description":"[en] Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects wpForo Forum: from n\/a through 3.0.6.","date":"2026-06-01"},{"id":"ee9e668414388ae32407388186c88dbfd1af9748","name":"wpForo Forum <= 3.0.6 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-306-missing-authorization","description":"The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-05-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"h","score":"9.1","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:H","score":"9.1","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f233eecea0bd907f3aa81e8ca9e299b96d8379ce4cab82b808f754ff0a56633b","name":"wpForo Forum [wpforo] < 3.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-49769","name":"CVE-2026-49769","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-49769","description":"[en] Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.","date":"2026-06-15"},{"id":"ee1ae3a011742ffb11382f18f3fccbf7035feeda","name":"wpForo Forum <= 3.1.0 - Unauthenticated PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-310-unauthenticated-php-object-injection","description":"The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2026-06-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"b4cd5e1889da0502f8b9814550584c303ff95a3180372a83788e02f477ec72f9","name":"wpForo Forum [wpforo] < 3.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-49767","name":"CVE-2026-49767","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-49767","description":"[en] Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.","date":"2026-06-17"},{"id":"c4571b28e2c12435f21503c2c1222261c090739e","name":"wpForo Forum <= 3.1.0 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-310-missing-authorization","description":"The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-06-04"},{"id":"EUVD-2026-37623","name":"EUVD-2026-37623","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-37623","description":"Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.","date":"2026-06-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-288","name":"Authentication Bypass Using an Alternate Path or Channel","description":"The product requires authentication, but the product has an alternate path or channel that does not require authentication."}]}},{"uuid":"fe4f2236811fb1d57dcd07883f16ec566e2390b162efb1afe78dca1f216c434a","name":"wpForo Forum [wpforo] < 3.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-57636","name":"CVE-2026-57636","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-57636","description":"[en] Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.","date":"2026-06-26"},{"id":"0d9c9b45eaa9369ced42f287f4b87f7400b6d76e","name":"wpForo Forum <= 3.0.9 - Authenticated (Contributor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/34e7688d-af94-4ba4-96a5-8b1ebbde8214","description":"The wpForo Forum plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-06-26"},{"id":"1b1188c28a4b477fd9abda2d7f451ebc429fb57c","name":"wpForo Forum &lt;= 3.0.9 - Authenticated (Contributor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-309-authenticated-contributor-sql-injection","description":"The wpForo Forum plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"8.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"8.5","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"efde0a328070ada92326fe732788903dbcfd2848f43c83f3b53794c9e012603c","name":"wpForo Forum [wpforo] < 3.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15021","name":"CVE-2026-15021","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15021","description":"[en] The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The sanitize_text_field() function applied at input does not encode double quotes, allowing attribute breakout via a payload that escapes the href attribute context and injects event handler attributes.","date":"2026-07-16"},{"id":"b3def651d1caf90ce4733b6cbfdc7ded64f52475","name":"wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-311-authenticated-subscriber-stored-cross-site-scripting-via-location-profile-field","description":"The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The sanitize_text_field() function applied at input does not encode double quotes, allowing attribute breakout via a payload that escapes the href attribute context and injects event handler attributes.","date":"2026-07-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c83d765da2651ea5de371a62fb1ed646e512d29ca65e885299213ec968df11c2","name":"wpForo Forum [wpforo] < 3.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12697","name":"CVE-2026-12697","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12697","description":"[en] The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.","date":"2026-07-31"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"db8707ef01722f9d2dc22de27273566d9be9fe9c3d940648d6899de685ed7089","name":"wpForo Forum [wpforo] < 3.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12696","name":"CVE-2026-12696","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12696","description":"[en] The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator.","date":"2026-08-01"},{"id":"8d755232f37cb0d0cb2bdb4c7eefd6e94cad5a06","name":"wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/7a4ab215-c5ee-4841-858a-e5e8d3199fb2","description":"The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-20"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3e646f49d899bd96db4fa0525d20afdb980550222291837782588f5f05c4782e","name":"wpForo Forum [wpforo] < 3.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12698","name":"CVE-2026-12698","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12698","description":"[en] The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score.","date":"2026-08-04"}],"impact":{"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"268768df597c1a78cbae52bcd203ca27fe61dcced850409671837a6551964d65","name":"wpForo Forum [wpforo] < 3.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5097","name":"CVE-2026-5097","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5097","description":"[en] The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-08-28"},{"id":"bfb8d45793c26dec3f2f715cb964bccfe8f09304","name":"wpForo Forum <= 2.4.17 - Unauthenticated SQL Injection via 'referer' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforo\/wpforo-forum-2417-unauthenticated-sql-injection-via-referer-parameter","description":"The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-07-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1788423297"}