Tomdever wpForo Forum

5 known vulnerabilities in Tomdever wpForo Forum, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-93747 CVSS 6.4 medium The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and…
  • CVE-2026-93772 CVSS 6.5 medium Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.
  • CVE-2026-91092 CVSS 4.3 medium The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to…
  • CVE-2026-5097 CVSS 7.5 high The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including…
  • CVE-2026-1581 CVSS 7.5 high The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and…