Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

wpForo Forum Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 45 vulnerability records associated with wpForo Forum, published between 2018 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

45Total records
4Critical
16High
25Medium
0Low
0Informational
45Patched records
0Currently marked unpatched
2018-05-27First disclosure
2026-07-15Latest disclosure
45 of 45CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201833 records
202044 records
202111 records
202277 records
202366 records
202433 records
202588 records
20261313 records

Severity Breakdown

SeverityRecordsShare
Critical48.9%
High1635.6%
Medium2555.6%

Vulnerability-Type Breakdown

Missing Authorization

10 records22.2%

First: 2022. Latest: 2026.

SQL Injection

8 records17.8%

First: 2018. Latest: 2026.

Cross-Site Scripting

8 records17.8%

First: 2018. Latest: 2026.

Other

6 records13.3%

First: 2021. Latest: 2026.

CSRF

5 records11.1%

First: 2020. Latest: 2023.

Privilege Escalation

3 records6.7%

First: 2018. Latest: 2025.

Path Traversal

3 records6.7%

First: 2026. Latest: 2026.

Arbitrary File Upload

1 record2.2%

First: 2022. Latest: 2022.

Information Disclosure

1 record2.2%

First: 2024. Latest: 2024.

Patch Status

Patched
45
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 3.1.2
  • 3.1.0
  • 3.1.1
  • 3.0.7
  • 3.0.5
  • 3.0.2
  • 3.0.6
  • 3.0.0
  • 3.0.3
  • 2.4.17
  • 2.4.15
  • 2.4.14
  • 2.4.13
  • 2.4.11
  • 2.4.10
  • 2.4.9
  • 2.4.7
  • 2.4.6
  • 2.4.4
  • 2.4.2
  • 2.3.5
  • 2.3.4
  • 2.2.6
  • 2.2.9
  • 2.2.4
  • 2.1.9
  • 2.1.8
  • 2.1.0
  • 2.0.6
  • 1.9.7
  • 1.7.0
  • 1.5.2
  • 1.4.12
  • 1.4.13

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-2.2.3wpForo Forum <= 2.2.3 - Authenticated (Subscriber+) Stored Cross-Site ScriptingNovember 20, 20232.2.4Medium
*-2.2.8wpForo Forum <= 2.2.8 - Cross-Site Request Forgery via logout()November 20, 20232.2.9Medium
*-2.2.3wpForo Forum <= 2.2.3 - Unauthenticated Privilege EscalationNovember 20, 20232.2.4Critical
*-2.1.8wpForo Forum <= 2.1.8 - Reflected Cross-Site Scripting via 'wpforo_debug'July 3, 20232.1.9Medium
*-2.1.7wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contentsJune 1, 20232.1.8High
*-2.0.9wpForo Forum <= 2.0.9 - Authenticated (Subscriber+) HTML InjectionDecember 7, 20222.1.0Medium
*-2.0.5wpForo Forum <= 2.0.5 - Insecure Direct Object Reference to Forum Privacy ChangeNovember 26, 20222.0.6Medium
*-2.0.9wpForo Forum <= 2.0.9 - Cross-Site Request ForgeryNovember 9, 20222.1.0High
*-2.0.9wpForo Forum <= 2.0.9 - Authenticated (Subscriber+) Arbitrary File UploadNovember 9, 20222.1.0High
*-2.0.5wpForo Forum <= 2.0.5 - Insecure Direct Object Reference to Forum Status ChangeSeptember 26, 20222.0.6Medium
*-2.0.5wpForo Forum <= 2.0.5 - Cross-Site Request ForgerySeptember 8, 20222.0.6High
*-2.0.5wpForo Forum <= 2.0.5 - Cross-Site Request ForgerySeptember 8, 20222.0.6High
*-1.9.6wpForo Forum <= 1.9.6 - Open RedirectJune 14, 20211.9.7Medium
*-1.6.5wpForo Forum <= 1.6.5 - Cross-Site Scripting via s parameterMay 4, 20201.7.0Medium
*-1.6.5wpForo Forum <= 1.6.5 - Cross-Site Scripting via wpf-dw-td-value classMay 4, 20201.7.0Medium
*-1.6.5wpForo Forum <= 1.6.5 - Cross-Site Request ForgeryMay 4, 20201.7.0High
*-1.6.5wpForo Forum <= 1.6.5 - Cross-Site Scripting via langid parameterMay 4, 20201.7.0Medium
*-1.5.1wpForo < = 1.5.1 - Privilege EscalationSeptember 6, 20181.5.2Critical
[*, 1.4.12)wpForo Forum < 1.4.12 - Reflected Cross-Site ScriptingJune 1, 20181.4.12Medium
*-1.4.12wpForo Forum <= 1.4.12 - SQL InjectionMay 27, 20181.4.13Critical

Selected source records

Latest Records

MediumCVE-2026-15021

wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field

Published: July 15, 2026

Affected versions
*-3.1.1
Patched versions
3.1.2
Original Wordfence record
MediumCVE-2026-57636

wpForo Forum <= 3.0.9 - Authenticated (Contributor+) SQL Injection

Published: June 26, 2026

Affected versions
*-3.0.9
Patched versions
3.1.0
Original Wordfence record
MediumCVE-2026-49767

wpForo Forum <= 3.1.0 - Missing Authorization

Published: June 4, 2026

Affected versions
*-3.1.0
Patched versions
3.1.1
Original Wordfence record
HighCVE-2026-49769

wpForo Forum <= 3.1.0 - Unauthenticated PHP Object Injection

Published: June 4, 2026

Affected versions
*-3.1.0
Patched versions
3.1.1
Original Wordfence record
MediumCVE-2026-42682

wpForo Forum <= 3.0.6 - Missing Authorization

Published: May 18, 2026

Affected versions
*-3.0.6
Patched versions
3.0.7
Original Wordfence record
HighCVE-2026-40798

wpForo Forum <= 3.0.4 - Unauthenticated SQL Injection

Published: May 7, 2026

Affected versions
*-3.0.4
Patched versions
3.0.5
Original Wordfence record
MediumCVE-2026-40767

wpForo Forum < 3.0.2 - Missing Authorization

Published: April 21, 2026

Affected versions
[*, 3.0.2)
Patched versions
3.0.2
Original Wordfence record
HighCVE-2026-6248

wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path

Published: April 20, 2026

Affected versions
*-3.0.5
Patched versions
3.0.6
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-3200

wpForo Forum <= 2.3.3 - Authenticated (Contributor+) SQL Injection

Published: May 31, 2024

Affected versions
*-2.3.3
Patched versions
2.3.4
Original Wordfence record
CriticalCVE-2023-47868

wpForo Forum <= 2.2.3 - Unauthenticated Privilege Escalation

Published: November 20, 2023

Affected versions
*-2.2.3
Patched versions
2.2.4
Original Wordfence record
CriticalCVE-2018-16613

wpForo < = 1.5.1 - Privilege Escalation

Published: September 6, 2018

Affected versions
*-1.5.1
Patched versions
1.5.2
Original Wordfence record
CriticalCVE-2018-11515

wpForo Forum <= 1.4.12 - SQL Injection

Published: May 27, 2018

Affected versions
*-1.4.12
Patched versions
1.4.13
Original Wordfence record
HighCVE-2022-40200

wpForo Forum <= 2.0.9 - Authenticated (Subscriber+) Arbitrary File Upload

Published: November 9, 2022

Affected versions
*-2.0.9
Patched versions
2.1.0
Original Wordfence record
HighCVE-2022-38144

wpForo Forum <= 2.0.5 - Cross-Site Request Forgery

Published: September 8, 2022

Affected versions
*-2.0.5
Patched versions
2.0.6
Original Wordfence record
HighCVE-2019-19109

wpForo Forum <= 1.6.5 - Cross-Site Request Forgery

Published: May 4, 2020

Affected versions
*-1.6.5
Patched versions
1.7.0
Original Wordfence record
HighCVE-2026-0910

wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object Injection

Published: February 10, 2026

Affected versions
*-2.4.13
Patched versions
2.4.14
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory