Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

wpForo Forum Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 45 vulnerability records associated with wpForo Forum, published between 2018 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

45Total records
4Critical
16High
25Medium
0Low
0Informational
45Patched records
0Currently marked unpatched
2018-05-27First disclosure
2026-07-15Latest disclosure
45 of 45CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201833 records
202044 records
202111 records
202277 records
202366 records
202433 records
202588 records
20261313 records

Severity Breakdown

SeverityRecordsShare
Critical48.9%
High1635.6%
Medium2555.6%

Vulnerability-Type Breakdown

Missing Authorization

10 records22.2%

First: 2022. Latest: 2026.

SQL Injection

8 records17.8%

First: 2018. Latest: 2026.

Cross-Site Scripting

8 records17.8%

First: 2018. Latest: 2026.

Other

6 records13.3%

First: 2021. Latest: 2026.

CSRF

5 records11.1%

First: 2020. Latest: 2023.

Privilege Escalation

3 records6.7%

First: 2018. Latest: 2025.

Path Traversal

3 records6.7%

First: 2026. Latest: 2026.

Arbitrary File Upload

1 record2.2%

First: 2022. Latest: 2022.

Information Disclosure

1 record2.2%

First: 2024. Latest: 2024.

Patch Status

Patched
45
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 3.1.2
  • 3.1.0
  • 3.1.1
  • 3.0.7
  • 3.0.5
  • 3.0.2
  • 3.0.6
  • 3.0.0
  • 3.0.3
  • 2.4.17
  • 2.4.15
  • 2.4.14
  • 2.4.13
  • 2.4.11
  • 2.4.10
  • 2.4.9
  • 2.4.7
  • 2.4.6
  • 2.4.4
  • 2.4.2
  • 2.3.5
  • 2.3.4
  • 2.2.6
  • 2.2.9
  • 2.2.4
  • 2.1.9
  • 2.1.8
  • 2.1.0
  • 2.0.6
  • 1.9.7
  • 1.7.0
  • 1.5.2
  • 1.4.12
  • 1.4.13

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-3.1.1wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile FieldJuly 15, 20263.1.2Medium
*-3.0.9wpForo Forum <= 3.0.9 - Authenticated (Contributor+) SQL InjectionJune 26, 20263.1.0Medium
*-3.1.0wpForo Forum <= 3.1.0 - Unauthenticated PHP Object InjectionJune 4, 20263.1.1High
*-3.1.0wpForo Forum <= 3.1.0 - Missing AuthorizationJune 4, 20263.1.1Medium
*-3.0.6wpForo Forum <= 3.0.6 - Missing AuthorizationMay 18, 20263.0.7Medium
*-3.0.4wpForo Forum <= 3.0.4 - Unauthenticated SQL InjectionMay 7, 20263.0.5High
[*, 3.0.2)wpForo Forum < 3.0.2 - Missing AuthorizationApril 21, 20263.0.2Medium
*-3.0.5wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File PathApril 20, 20263.0.6High
*-2.4.16wpForo Forum <= 2.4.16 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Forum Post Modification via 'guestposting' ParameterApril 16, 20263.0.0Medium
*-3.0.2wpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' ParameterApril 10, 20263.0.3High
*-2.4.16wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post BodyApril 3, 20262.4.17High
*-2.4.14wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL InjectionFebruary 18, 20262.4.15High
*-2.4.13wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object InjectionFebruary 10, 20262.4.14High
*-2.4.12wpForo Forum <= 2.4.12 - Unauthenticated SQL InjectionDecember 13, 20252.4.13High
*-2.4.10wpForo Forum <= 2.4.10 - Missing AuthorizationNovember 18, 20252.4.11Medium
*-2.4.9wpForo Forum <= 2.4.9 - Authenticated (Susbscriber+) SQL InjectionOctober 31, 20252.4.10Medium
*-2.4.8wpForo Forum <= 2.4.8 - Unauthenticated SQL Injection via get_members FunctionOctober 24, 20252.4.9High
*-2.4.6wpForo Forum <= 2.4.6 - Authenticated (Subscriber+) Insecure Direct Object ReferenceSeptember 3, 20252.4.7Medium
*-2.4.5wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile AvatarJuly 9, 20252.4.6Medium
*-2.4.3wpForo Forum <= 2.4.3 - Authenticated (Subscriber+) Privilege EscalationApril 2, 20252.4.4High
*-2.4.1wpForo Forum <= 2.4.1 - Authenticated (Subscriber+) Arbitrary File Read in updateFebruary 27, 20252.4.2Medium
*-2.3.4wpForo Forum <= 2.3.4 - Authenticated (Subscriber+) Insecure Direct Object ReferenceAugust 16, 20242.3.5Medium
*-2.3.4wpForo Forum <= 2.3.4 - Unauthenticated Sensitive Information ExposureAugust 16, 20242.3.5Medium
*-2.3.3wpForo Forum <= 2.3.3 - Authenticated (Contributor+) SQL InjectionMay 31, 20242.3.4Critical
*-2.2.5wpForo Forum <= 2.2.5 - Missing AuthorizationNovember 20, 20232.2.6Medium

Selected source records

Latest Records

MediumCVE-2026-15021

wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field

Published: July 15, 2026

Affected versions
*-3.1.1
Patched versions
3.1.2
Original Wordfence record
MediumCVE-2026-57636

wpForo Forum <= 3.0.9 - Authenticated (Contributor+) SQL Injection

Published: June 26, 2026

Affected versions
*-3.0.9
Patched versions
3.1.0
Original Wordfence record
MediumCVE-2026-49767

wpForo Forum <= 3.1.0 - Missing Authorization

Published: June 4, 2026

Affected versions
*-3.1.0
Patched versions
3.1.1
Original Wordfence record
HighCVE-2026-49769

wpForo Forum <= 3.1.0 - Unauthenticated PHP Object Injection

Published: June 4, 2026

Affected versions
*-3.1.0
Patched versions
3.1.1
Original Wordfence record
MediumCVE-2026-42682

wpForo Forum <= 3.0.6 - Missing Authorization

Published: May 18, 2026

Affected versions
*-3.0.6
Patched versions
3.0.7
Original Wordfence record
HighCVE-2026-40798

wpForo Forum <= 3.0.4 - Unauthenticated SQL Injection

Published: May 7, 2026

Affected versions
*-3.0.4
Patched versions
3.0.5
Original Wordfence record
MediumCVE-2026-40767

wpForo Forum < 3.0.2 - Missing Authorization

Published: April 21, 2026

Affected versions
[*, 3.0.2)
Patched versions
3.0.2
Original Wordfence record
HighCVE-2026-6248

wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path

Published: April 20, 2026

Affected versions
*-3.0.5
Patched versions
3.0.6
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-3200

wpForo Forum <= 2.3.3 - Authenticated (Contributor+) SQL Injection

Published: May 31, 2024

Affected versions
*-2.3.3
Patched versions
2.3.4
Original Wordfence record
CriticalCVE-2023-47868

wpForo Forum <= 2.2.3 - Unauthenticated Privilege Escalation

Published: November 20, 2023

Affected versions
*-2.2.3
Patched versions
2.2.4
Original Wordfence record
CriticalCVE-2018-16613

wpForo < = 1.5.1 - Privilege Escalation

Published: September 6, 2018

Affected versions
*-1.5.1
Patched versions
1.5.2
Original Wordfence record
CriticalCVE-2018-11515

wpForo Forum <= 1.4.12 - SQL Injection

Published: May 27, 2018

Affected versions
*-1.4.12
Patched versions
1.4.13
Original Wordfence record
HighCVE-2022-40200

wpForo Forum <= 2.0.9 - Authenticated (Subscriber+) Arbitrary File Upload

Published: November 9, 2022

Affected versions
*-2.0.9
Patched versions
2.1.0
Original Wordfence record
HighCVE-2022-38144

wpForo Forum <= 2.0.5 - Cross-Site Request Forgery

Published: September 8, 2022

Affected versions
*-2.0.5
Patched versions
2.0.6
Original Wordfence record
HighCVE-2019-19109

wpForo Forum <= 1.6.5 - Cross-Site Request Forgery

Published: May 4, 2020

Affected versions
*-1.6.5
Patched versions
1.7.0
Original Wordfence record
HighCVE-2026-0910

wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object Injection

Published: February 10, 2026

Affected versions
*-2.4.13
Patched versions
2.4.14
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory