Missing Authorization
10 records22.2%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 45 vulnerability records associated with wpForo Forum, published between 2018 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2018 | 3 | |
| 2020 | 4 | |
| 2021 | 1 | |
| 2022 | 7 | |
| 2023 | 6 | |
| 2024 | 3 | |
| 2025 | 8 | |
| 2026 | 13 |
| Severity | Records | Share |
|---|---|---|
| Critical | 4 | 8.9% |
| High | 16 | 35.6% |
| Medium | 25 | 55.6% |
First: 2022. Latest: 2026.
First: 2018. Latest: 2026.
First: 2018. Latest: 2026.
First: 2021. Latest: 2026.
First: 2020. Latest: 2023.
First: 2018. Latest: 2025.
First: 2026. Latest: 2026.
First: 2022. Latest: 2022.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.1.23.1.03.1.13.0.73.0.53.0.23.0.63.0.03.0.32.4.172.4.152.4.142.4.132.4.112.4.102.4.92.4.72.4.62.4.42.4.22.3.52.3.42.2.62.2.92.2.42.1.92.1.82.1.02.0.61.9.71.7.01.5.21.4.121.4.13Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.1.1 | wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field | July 15, 2026 | 3.1.2 | Medium |
*-3.0.9 | wpForo Forum <= 3.0.9 - Authenticated (Contributor+) SQL Injection | June 26, 2026 | 3.1.0 | Medium |
*-3.1.0 | wpForo Forum <= 3.1.0 - Unauthenticated PHP Object Injection | June 4, 2026 | 3.1.1 | High |
*-3.1.0 | wpForo Forum <= 3.1.0 - Missing Authorization | June 4, 2026 | 3.1.1 | Medium |
*-3.0.6 | wpForo Forum <= 3.0.6 - Missing Authorization | May 18, 2026 | 3.0.7 | Medium |
*-3.0.4 | wpForo Forum <= 3.0.4 - Unauthenticated SQL Injection | May 7, 2026 | 3.0.5 | High |
[*, 3.0.2) | wpForo Forum < 3.0.2 - Missing Authorization | April 21, 2026 | 3.0.2 | Medium |
*-3.0.5 | wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path | April 20, 2026 | 3.0.6 | High |
*-2.4.16 | wpForo Forum <= 2.4.16 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Forum Post Modification via 'guestposting' Parameter | April 16, 2026 | 3.0.0 | Medium |
*-3.0.2 | wpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter | April 10, 2026 | 3.0.3 | High |
*-2.4.16 | wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body | April 3, 2026 | 2.4.17 | High |
*-2.4.14 | wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection | February 18, 2026 | 2.4.15 | High |
*-2.4.13 | wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object Injection | February 10, 2026 | 2.4.14 | High |
*-2.4.12 | wpForo Forum <= 2.4.12 - Unauthenticated SQL Injection | December 13, 2025 | 2.4.13 | High |
*-2.4.10 | wpForo Forum <= 2.4.10 - Missing Authorization | November 18, 2025 | 2.4.11 | Medium |
*-2.4.9 | wpForo Forum <= 2.4.9 - Authenticated (Susbscriber+) SQL Injection | October 31, 2025 | 2.4.10 | Medium |
*-2.4.8 | wpForo Forum <= 2.4.8 - Unauthenticated SQL Injection via get_members Function | October 24, 2025 | 2.4.9 | High |
*-2.4.6 | wpForo Forum <= 2.4.6 - Authenticated (Subscriber+) Insecure Direct Object Reference | September 3, 2025 | 2.4.7 | Medium |
*-2.4.5 | wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar | July 9, 2025 | 2.4.6 | Medium |
*-2.4.3 | wpForo Forum <= 2.4.3 - Authenticated (Subscriber+) Privilege Escalation | April 2, 2025 | 2.4.4 | High |
*-2.4.1 | wpForo Forum <= 2.4.1 - Authenticated (Subscriber+) Arbitrary File Read in update | February 27, 2025 | 2.4.2 | Medium |
*-2.3.4 | wpForo Forum <= 2.3.4 - Authenticated (Subscriber+) Insecure Direct Object Reference | August 16, 2024 | 2.3.5 | Medium |
*-2.3.4 | wpForo Forum <= 2.3.4 - Unauthenticated Sensitive Information Exposure | August 16, 2024 | 2.3.5 | Medium |
*-2.3.3 | wpForo Forum <= 2.3.3 - Authenticated (Contributor+) SQL Injection | May 31, 2024 | 2.3.4 | Critical |
*-2.2.5 | wpForo Forum <= 2.2.5 - Missing Authorization | November 20, 2023 | 2.2.6 | Medium |
Selected source records
Published: July 15, 2026
Published: June 26, 2026
Published: June 4, 2026
Published: June 4, 2026
Published: May 18, 2026
Published: May 7, 2026
Published: April 21, 2026
Published: April 20, 2026
Published: May 31, 2024
Published: November 20, 2023
Published: September 6, 2018
Published: May 27, 2018
Published: November 9, 2022
Published: September 8, 2022
Published: May 4, 2020
Published: February 10, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.