Product
gvectors wpforo forum
29 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-28562
CVE-2026-28561
CVE-2026-28560
CVE-2026-28559
CVE-2026-28558
CVE-2026-28557
CVE-2026-28556
CVE-2026-28555
CVE-2026-28554
CVE-2025-0764
CVE-2023-47869
CVE-2024-43289
CVE-2024-43288
CVE-2022-38055
CVE-2024-3200
CVE-2023-47868
CVE-2023-47870
CVE-2023-47872
CVE-2023-2309
CVE-2023-2249
CVE-2022-40200
CVE-2022-40192
CVE-2022-40632
CVE-2022-40206
CVE-2022-40205
CVE-2022-38144
CVE-2021-24406
CVE-2018-16613
CVE-2018-11709
>= 2.4.0 and < 2.4.15
wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on
>= 2.4.0 and < 2.4.16
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent JavaScrip
>= 2.4.0 and < 2.4.16
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows script injection via forum URL data output in
>= 2.4.0 and < 2.4.16
wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and una
>= 2.4.0 and < 2.4.16
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files
>= 2.4.0 and < 2.4.16
wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo userg
>= 2.4.0 and < 2.4.16
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split
>= 2.4.0 and < 2.4.16
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reopen any fo
>= 2.4.0 and < 2.4.16
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or unapprove a
< 2.4.2
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' me
< 2.2.6
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows C
< 2.3.5
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo F
< 2.3.5
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from
< 2.1.0
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows C
< 2.3.4
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all ver
< 2.2.4
Improper Privilege Management vulnerability in wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: fr
<= 2.2.6
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Requ
<= 2.2.3
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum a
< 2.1.9
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected
<= 2.1.7
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization i
<= 2.0.9
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
<= 2.0.9
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
<= 2.0.5
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deleti
<= 2.0.5
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subs
<= 2.0.5
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subs
<= 2.0.5
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.
< 1.9.7
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading
< 1.5.2
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able t
< 1.4.12
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated