#wpForo
wpForo Forum expone sitios a inyección de objetos PHP

¿Tu foro corre wpForo? La vulnerabilidad wpForo WordPress CVE-2026-80513 permite inyección PHP con un simple Suscriptor. Revisá tu versión ahora

#wpforo #cve202680513 #deserializacionphp #pluginswordpress #seguridadwordpress
wpForo Forum expone sitios a inyección de objetos PHP - Seguridad en Wordpress
CVE-2026-80513 permite inyección de objetos PHP en wpForo Forum antes de 3.1.6 a través de un campo de perfil, con CVSS 8.0 según wpscan.com.
seguridadenwordpress.com
September 24, 2026 at 10:14 AM
Migrated from bbPress or wpForo? Your moderation history comes with you now. Settings that said saved actually apply. And after this update your counters quietly recount themselves in the background, no manual fixing required.

wbcomdesigns.com/release-note...
September 24, 2026 at 6:11 PM
CVE-2026-49767 wpforo (CVSS Score 5.3)

#WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #hacking #wpsecurity #atomicedge #cybersecurity #malware #vulnerabilityresearch #cve #redteam #proofofconcept
CVE-2026-49767 – wpforo Proof of Concept - Atomic Edge
CVE-2026-49767 vulnerability in wpforo WordPress plugin. Proof of concept, ModSecurity rule, and patched version analysis by Atomic Edge.
atomicedge.io
June 15, 2026 at 9:16 PM
🚨 EUVD-2026-86591
📊 6.4/10
🏢 tomdever

📝 The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86591

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 9:03 AM
🚨 EUVD-2026-85796
📊 n/a
🏢 Unknown

📝 The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85796

#cybersecurity #infosec #cve #euvd
September 24, 2026 at 7:01 AM
bbPress vs wpForo vs Jetonomy: The Past, The Present, and The Future of WordPress Communities

A hands-on comparison of bbPress, wpForo, and Jetonomy from someone who has built WordPress communities with all three — features, performance, BuddyPress integration, and which to choose.
bbPress vs wpForo vs Jetonomy: The Past, The Present, and The Future of WordPress Communities
A hands-on comparison of bbPress, wpForo, and Jetonomy from someone who has built WordPress communities with all three — features, performance, BuddyPress integration, and which to choose.
vapvarun.com
March 25, 2026 at 8:58 AM
Turn your LMS into a social learning hub! 🎓💬
LearnDash wpForo links courses with interactive forums for discussions, questions & peer support.

🔗 bit.ly/4aPlQyp

#LearnDash #wpForo #WordPressLMS #ELearningCommunity
December 8, 2025 at 3:00 PM
CVE-2026-28559 - wpForo Forum 2.4.14 Information Disclosure via Global RSS Feed
CVE ID : CVE-2026-28559

Published : Feb. 28, 2026, 10:16 p.m. | 1 hour, 23 minutes ago

Description : wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthent...
CVE-2026-28559 - wpForo Forum 2.4.14 Information Disclosure via Global RSS Feed
wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topics via the global RSS feed endpoint. Attackers request the RSS feed without a forum ID parameter, bypassing the privacy and status WHERE clauses that are only applied when a specific forum …
cvefeed.io
March 1, 2026 at 12:02 AM
CVE-2026-28560 - wpForo Forum 2.4.14 Stored XSS via Unsafe JSON Encoding in Inline Script
CVE ID : CVE-2026-28560

Published : Feb. 28, 2026, 10:16 p.m. | 1 hour, 23 minutes ago

Description : wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that al...
CVE-2026-28560 - wpForo Forum 2.4.14 Stored XSS via Unsafe JSON Encoding in Inline Script
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows script injection via forum URL data output into an inline script block using json_encode without the JSON_HEX_TAG flag. Attackers set a forum slug containing a closing script tag or unescaped single quote to break out of the JavaScript string …
cvefeed.io
March 1, 2026 at 12:22 AM
wpForo Forum 2.4.14 Stored XSS via SVG Avatar File UploadwpForo Forum 2.4.14 ... wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to up...

Origin | Interest | Match
CVE-2026-28558 | THREATINT
CVE-2026-28558: wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript ...
cve.threatint.eu
February 28, 2026 at 11:25 PM
CVE-2026-28561 - wpForo Forum 2.4.14 Stored XSS via Unescaped Forum Description in Templates
CVE ID : CVE-2026-28561

Published : Feb. 28, 2026, 10:16 p.m. | 1 hour, 23 minutes ago

Description : wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that...
CVE-2026-28561 - wpForo Forum 2.4.14 Stored XSS via Unescaped Forum Description in Templates
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent JavaScript via forum description fields echoed without output escaping across multiple theme template files. On multisite installations or with a compromised admin account, attackers set a forum description containing HTML event handlers that execute when …
cvefeed.io
March 1, 2026 at 12:12 AM
CVE-2026-28558 - wpForo Forum 2.4.14 Stored XSS via SVG Avatar File Upload
CVE ID : CVE-2026-28558

Published : Feb. 28, 2026, 10:16 p.m. | 1 hour, 23 minutes ago

Description : wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authentica...
CVE-2026-28558 - wpForo Forum 2.4.14 Stored XSS via SVG Avatar File Upload
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user who views the attacker's profile …
cvefeed.io
February 28, 2026 at 11:58 PM
📝解離性障害のサイトに使うレンタル掲示板を探してたけど、WordPressにフツーにプラグインがあるのか…。
楽しそう👀使ってみたい🕺
こんなの全部使いこなせたら、小さな小さなSNSが出来てしまうな。SUGOI。
wordpresso.jp/plug-in/4580/

#私にもデジタルが使える
wpForo-掲示板だけで世界を作りたい人へ
https://wordpress.org/plugins/wpforo/ これはもう紹介済みかとおもっていたら紹介していなかった。
wordpresso.jp
June 14, 2025 at 4:22 PM
🚨 EUVD-2026-9111
📊 8.8/10
🏢 gVectors Team

📝 wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql(...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9111

#cybersecurity #infosec #cve #euvd
February 28, 2026 at 11:01 PM
🚨 EUVD-2026-9110
📊 4.8/10
🏢 gVectors Team

📝 wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent JavaScript via forum descript...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9110

#cybersecurity #infosec #cve #euvd
February 28, 2026 at 11:01 PM
🚨 EUVD-2026-52583
📊 n/a
🏢 Unknown

📝 The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52583

#cybersecurity #infosec #cve #euvd
August 4, 2026 at 7:00 AM
🚨 EUVD-2026-51698
📊 n/a
🏢 Unknown

📝 The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-51698

#cybersecurity #infosec #cve #euvd
August 1, 2026 at 7:01 AM
🚨 EUVD-2026-51437
📊 n/a
🏢 Unknown

📝 The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allo...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-51437

#cybersecurity #infosec #cve #euvd
July 31, 2026 at 7:01 AM
Thanks for sharing. For those using wpForo, ensure you’ve updated to the latest patched version immediately to mitigate this vulnerability. Always keep plugins updated to stay secure! #WordPress #InfoSec
June 15, 2026 at 9:40 PM
🔴 CVE-2026-49769 - Critical (9.8)

Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.

https://www.thehackerwire.com/vulnerability/CVE-2026-49769/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
June 16, 2026 at 6:00 AM
🔴 CVE-2026-42682 - Critical (9.1)

Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Config...

https://www.thehackerwire.com/vulnerability/CVE-2026-42682/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
June 1, 2026 at 5:00 PM
🟠 CVE-2026-6248 - High (8.1)

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to ...

https://www.thehackerwire.com/vulnerability/CVE-2026-6248/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
April 20, 2026 at 8:00 PM
🟠 CVE-2026-3666 - High (8.8)

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up...

https://www.thehackerwire.com/vulnerability/CVE-2026-3666/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
April 5, 2026 at 3:01 AM
🟠 CVE-2026-3666 - High (8.8)

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up...

https://www.thehackerwire.com/vulnerability/CVE-2026-3666/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
April 5, 2026 at 3:01 AM
🟠 CVE-2026-28562 - High (8.2)

wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() whe...

https://www.thehackerwire.com/vulnerability/CVE-2026-28562/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
March 1, 2026 at 4:26 AM