« Volver al listado

Gvectors

Gvectors Wpforo: vulnerabilidades y CVE

Gvectors Wpforo tiene 29 vulnerabilidades publicadas, 21 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE29
Últimos 12 meses21
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-80514Media (5.3)0.16%—25 sept 2026
The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing…
CVE-2026-93747Media (6.4)0.20%—25 sept 2026
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output…
CVE-2026-91092Media (4.3)0.39%—22 sept 2026
The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action.…
CVE-2026-5097Alta (7.5)0.55%—28 ago 2026
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack…
CVE-2026-12698Media (4.3)0.25%—4 ago 2026
The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled…
CVE-2026-12696Media (5.4)0.23%—1 ago 2026
The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a…
CVE-2026-15021Media (6.4)0.36%—16 jul 2026
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping.…
CVE-2026-57636Alta (8.5)0.36%—26 jun 2026
Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.
CVE-2026-49767Crítica (9.8)0.61%—17 jun 2026
Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.
CVE-2026-49769Crítica (9.8)0.56%—15 jun 2026
Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
CVE-2026-40767Alta (7.5)0.39%—15 jun 2026
Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.
CVE-2026-6248Alta (8.1)0.95%—20 abr 2026
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the…
CVE-2026-4666Media (6.5)0.45%—17 abr 2026
The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all…
CVE-2026-5809Alta (7.1)0.63%—11 abr 2026
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept…
CVE-2026-3666Alta (8.8)0.58%—4 abr 2026
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This…
CVE-2026-1581Alta (7.5)1.7%—19 feb 2026
The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack…
CVE-2026-0910Alta (8.8)0.53%—11 feb 2026
The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it…
CVE-2025-66070Alta (7.5)0.28%—18 dic 2025
Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.10.
CVE-2025-13126Alta (7.5)0.38%—14 dic 2025
The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied…
CVE-2025-11740Media (6.5)0.26%—1 nov 2025
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of…
CVE-2025-4203Alta (7.5)0.37%—25 oct 2025
The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset'…
CVE-2025-58597Media (4.3)0.34%—3 sept 2025
Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <=…
CVE-2025-4406Media (5.4)0.23%—10 jul 2025
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes…
CVE-2025-4224Alta (7.2)0.24%—3 jun 2025
The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and…
CVE-2019-19112Media (6.1)0.93%—15 jun 2020
The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.
CVE-2019-19111Media (6.1)0.93%—15 jun 2020
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.
CVE-2019-19110Media (4.8)0.71%—15 jun 2020
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
CVE-2019-19109Alta (8.8)0.71%—15 jun 2020
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
CVE-2018-11515Crítica (9.8)1.7%—28 may 2018
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1005 Data from Local System2
  3. T1210 Exploitation of Remote Services2
  4. T1059.007 JavaScript1
  5. T1499.004 Application or System Exploitation1
  6. T1565.002 Transmitted Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Gvectors