Missing Authorization
10 records22.2%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 45 vulnerability records associated with wpForo Forum, published between 2018 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2018 | 3 | |
| 2020 | 4 | |
| 2021 | 1 | |
| 2022 | 7 | |
| 2023 | 6 | |
| 2024 | 3 | |
| 2025 | 8 | |
| 2026 | 13 |
| Severity | Records | Share |
|---|---|---|
| Critical | 4 | 8.9% |
| High | 16 | 35.6% |
| Medium | 25 | 55.6% |
First: 2022. Latest: 2026.
First: 2018. Latest: 2026.
First: 2018. Latest: 2026.
First: 2021. Latest: 2026.
First: 2020. Latest: 2023.
First: 2018. Latest: 2025.
First: 2026. Latest: 2026.
First: 2022. Latest: 2022.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.1.23.1.03.1.13.0.73.0.53.0.23.0.63.0.03.0.32.4.172.4.152.4.142.4.132.4.112.4.102.4.92.4.72.4.62.4.42.4.22.3.52.3.42.2.62.2.92.2.42.1.92.1.82.1.02.0.61.9.71.7.01.5.21.4.121.4.13Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.2.3 | wpForo Forum <= 2.2.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting | November 20, 2023 | 2.2.4 | Medium |
*-2.2.8 | wpForo Forum <= 2.2.8 - Cross-Site Request Forgery via logout() | November 20, 2023 | 2.2.9 | Medium |
*-2.2.3 | wpForo Forum <= 2.2.3 - Unauthenticated Privilege Escalation | November 20, 2023 | 2.2.4 | Critical |
*-2.1.8 | wpForo Forum <= 2.1.8 - Reflected Cross-Site Scripting via 'wpforo_debug' | July 3, 2023 | 2.1.9 | Medium |
*-2.1.7 | wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents | June 1, 2023 | 2.1.8 | High |
*-2.0.9 | wpForo Forum <= 2.0.9 - Authenticated (Subscriber+) HTML Injection | December 7, 2022 | 2.1.0 | Medium |
*-2.0.5 | wpForo Forum <= 2.0.5 - Insecure Direct Object Reference to Forum Privacy Change | November 26, 2022 | 2.0.6 | Medium |
*-2.0.9 | wpForo Forum <= 2.0.9 - Cross-Site Request Forgery | November 9, 2022 | 2.1.0 | High |
*-2.0.9 | wpForo Forum <= 2.0.9 - Authenticated (Subscriber+) Arbitrary File Upload | November 9, 2022 | 2.1.0 | High |
*-2.0.5 | wpForo Forum <= 2.0.5 - Insecure Direct Object Reference to Forum Status Change | September 26, 2022 | 2.0.6 | Medium |
*-2.0.5 | wpForo Forum <= 2.0.5 - Cross-Site Request Forgery | September 8, 2022 | 2.0.6 | High |
*-2.0.5 | wpForo Forum <= 2.0.5 - Cross-Site Request Forgery | September 8, 2022 | 2.0.6 | High |
*-1.9.6 | wpForo Forum <= 1.9.6 - Open Redirect | June 14, 2021 | 1.9.7 | Medium |
*-1.6.5 | wpForo Forum <= 1.6.5 - Cross-Site Scripting via s parameter | May 4, 2020 | 1.7.0 | Medium |
*-1.6.5 | wpForo Forum <= 1.6.5 - Cross-Site Scripting via wpf-dw-td-value class | May 4, 2020 | 1.7.0 | Medium |
*-1.6.5 | wpForo Forum <= 1.6.5 - Cross-Site Request Forgery | May 4, 2020 | 1.7.0 | High |
*-1.6.5 | wpForo Forum <= 1.6.5 - Cross-Site Scripting via langid parameter | May 4, 2020 | 1.7.0 | Medium |
*-1.5.1 | wpForo < = 1.5.1 - Privilege Escalation | September 6, 2018 | 1.5.2 | Critical |
[*, 1.4.12) | wpForo Forum < 1.4.12 - Reflected Cross-Site Scripting | June 1, 2018 | 1.4.12 | Medium |
*-1.4.12 | wpForo Forum <= 1.4.12 - SQL Injection | May 27, 2018 | 1.4.13 | Critical |
Selected source records
Published: July 15, 2026
Published: June 26, 2026
Published: June 4, 2026
Published: June 4, 2026
Published: May 18, 2026
Published: May 7, 2026
Published: April 21, 2026
Published: April 20, 2026
Published: May 31, 2024
Published: November 20, 2023
Published: September 6, 2018
Published: May 27, 2018
Published: November 9, 2022
Published: September 8, 2022
Published: May 4, 2020
Published: February 10, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.