sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total47
Critical5
High16
Medium26
Reset
Showing 21-40 of 47 records
Threat Entry Updated 2026-06-17

Wpforo Forum - Broken Access Control (CVE-2026-28554)

wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or unapprove any forum post via the wpforo_approve_ajax AJAX handler. Attackers exploit the nonce-only check by submitting a valid nonce with an arbitrary post ID to bypass moderation controls entirely.

PLUGIN Wpforo Forum

CVE-2026-28554

MEDIUM CVSS 5.3 2026-02-28
Threat Entry Updated 2026-06-17

wpForo Forum - SQL Injection (CVE-2026-1581)

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN wpForo Forum

CVE-2026-1581

HIGH CVSS 7.5 2026-02-19
Threat Entry Updated 2026-06-17

wpForo Forum - PHP Object Injection (CVE-2026-0910)

The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed…

PLUGIN wpForo Forum

CVE-2026-0910

HIGH CVSS 8.8 2026-02-11
Threat Entry Updated 2026-06-17

wpForo Forum - SQL Injection (CVE-2025-13126)

The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN wpForo Forum

CVE-2025-13126

HIGH CVSS 7.5 2025-12-14
Threat Entry Updated 2026-06-17

wpForo Forum - SQL Injection (CVE-2025-11740)

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN wpForo Forum

CVE-2025-11740

MEDIUM CVSS 6.5 2025-11-01
Threat Entry Updated 2026-06-17

wpForo Forum - SQL Injection (CVE-2025-4203)

The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x’s grammar allows a 'PROCEDURE ANALYSE' clause immediately after a LIMIT clause. Unauthenticated attackers controlling 'row_count' can append a stored‐procedure call, enabling error‐based or time‐based blind SQL injection that can be used to extract sensitive…

PLUGIN wpForo Forum

CVE-2025-4203

HIGH CVSS 7.5 2025-10-25
Threat Entry Updated 2026-06-17

wpForo Forum - Cross-Site Scripting (XSS) (CVE-2025-4406)

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN wpForo Forum

CVE-2025-4406

MEDIUM CVSS 5.4 2025-07-10
Threat Entry Updated 2026-06-17

Wpforo Forum - Security Vulnerability (CVE-2025-0764)

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.

PLUGIN Wpforo Forum

CVE-2025-0764

MEDIUM CVSS 6.5 2025-02-28
Threat Entry Updated 2026-06-17

Wpforo Forum - SQL Injection (CVE-2024-3200)

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wpforo Forum

CVE-2024-3200

CRITICAL CVSS 9.9 2024-06-01
Threat Entry Updated 2026-06-17

Wpforo Forum - Broken Access Control (CVE-2023-47870)

Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6.

PLUGIN Wpforo Forum

CVE-2023-47870

MEDIUM CVSS 5.7 2023-11-30
Threat Entry Updated 2026-06-17

Wpforo Forum - Remote Code Execution (CVE-2023-2249)

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.

PLUGIN Wpforo Forum

CVE-2023-2249

HIGH CVSS 8.8 2023-06-09