Gvectors
Gvectors Wpforo: vulnerabilidades y CVE
Gvectors Wpforo tiene 29 vulnerabilidades publicadas, 21 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses21
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-80514 | Media (5.3) | 0.16% | — | 25 sept 2026 | The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing… |
| CVE-2026-93747 | Media (6.4) | 0.20% | — | 25 sept 2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output… |
| CVE-2026-91092 | Media (4.3) | 0.39% | — | 22 sept 2026 | The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action.… |
| CVE-2026-5097 | Alta (7.5) | 0.55% | — | 28 ago 2026 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack… |
| CVE-2026-12698 | Media (4.3) | 0.25% | — | 4 ago 2026 | The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled… |
| CVE-2026-12696 | Media (5.4) | 0.23% | — | 1 ago 2026 | The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a… |
| CVE-2026-15021 | Media (6.4) | 0.36% | — | 16 jul 2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping.… |
| CVE-2026-57636 | Alta (8.5) | 0.36% | — | 26 jun 2026 | Contributor SQL Injection in wpForo Forum <= 3.0.9 versions. |
| CVE-2026-49767 | Crítica (9.8) | 0.61% | — | 17 jun 2026 | Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. |
| CVE-2026-49769 | Crítica (9.8) | 0.56% | — | 15 jun 2026 | Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. |
| CVE-2026-40767 | Alta (7.5) | 0.39% | — | 15 jun 2026 | Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions. |
| CVE-2026-6248 | Alta (8.1) | 0.95% | — | 20 abr 2026 | The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the… |
| CVE-2026-4666 | Media (6.5) | 0.45% | — | 17 abr 2026 | The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all… |
| CVE-2026-5809 | Alta (7.1) | 0.63% | — | 11 abr 2026 | The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept… |
| CVE-2026-3666 | Alta (8.8) | 0.58% | — | 4 abr 2026 | The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This… |
| CVE-2026-1581 | Alta (7.5) | 1.7% | — | 19 feb 2026 | The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack… |
| CVE-2026-0910 | Alta (8.8) | 0.53% | — | 11 feb 2026 | The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it… |
| CVE-2025-66070 | Alta (7.5) | 0.28% | — | 18 dic 2025 | Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.10. |
| CVE-2025-13126 | Alta (7.5) | 0.38% | — | 14 dic 2025 | The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied… |
| CVE-2025-11740 | Media (6.5) | 0.26% | — | 1 nov 2025 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of… |
| CVE-2025-4203 | Alta (7.5) | 0.37% | — | 25 oct 2025 | The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset'… |
| CVE-2025-58597 | Media (4.3) | 0.34% | — | 3 sept 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <=… |
| CVE-2025-4406 | Media (5.4) | 0.23% | — | 10 jul 2025 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes… |
| CVE-2025-4224 | Alta (7.2) | 0.24% | — | 3 jun 2025 | The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and… |
| CVE-2019-19112 | Media (6.1) | 0.93% | — | 15 jun 2020 | The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php. |
| CVE-2019-19111 | Media (6.1) | 0.93% | — | 15 jun 2020 | The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter. |
| CVE-2019-19110 | Media (4.8) | 0.71% | — | 15 jun 2020 | The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter. |
| CVE-2019-19109 | Alta (8.8) | 0.71% | — | 15 jun 2020 | The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. |
| CVE-2018-11515 | Crítica (9.8) | 1.7% | — | 28 may 2018 | The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.