WP Forum Server <= 1.8.2 - Authenticated (Administrator+) SQL Injection
medium
The WP Forum Server plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access...
- CVSS:
- 4.9
- Affected:
- up to 1.8.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53306 on NVD →
WP Forum Server <= 1.8.2 - Cross-Site Request Forgery
medium
The WP Forum Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site admin...
- CVSS:
- 4.3
- Affected:
- up to 1.8.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53305 on NVD →
WP Forum Server [forum-server] <= 1.8.2 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server allows Stored XSS. This issue affects WP Forum Server: from n/a through 1.8.2.
- Affected:
- up to 1.8.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53305 on NVD →
WP Forum Server [forum-server] <= 1.8.2 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in lucidcrew WP Forum Server allows SQL Injection. This issue affects WP Forum Server: from n/a through 1.8.2.
- Affected:
- up to 1.8.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53306 on NVD →
WP Forum Server [forum-server] < 1.7.4
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) groupid parameter in an editgroup action or (2) usergroup_id parameter in an edit_usergroup acti...
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Jan 16, 2014
CVE-2012-6622 on NVD →
WP Forum Server [forum-server] < 1.7.5
unknown
[en] Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php in the ForumPress WP Forum Server plugin before 1.7.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the groupid parameter in an addforum action to wp-admin/admin.php.
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.5
- Disclosed:
- Jan 16, 2014
CVE-2012-6623 on NVD →
WP Forum Server [forum-server] < 1.7.4
unknown
[en] SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action.
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Jan 16, 2014
CVE-2012-6625 on NVD →
WP Forum Server < 1.7.4 - SQL Injection
high
SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action.
- CVSS:
- 7.2
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- May 15, 2012
CVE-2012-6625 on NVD →
WP Forum Server < 1.7.5 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php in the ForumPress WP Forum Server plugin before 1.7.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the groupid parameter in an addforum action to wp-admin/admin.php.
- CVSS:
- 7.1
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.5
- Disclosed:
- May 15, 2012
CVE-2012-6623 on NVD →
WP Forum Server <= 1.7.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WP Forum Server plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the (1) groupid parameter in an editgroup action or (2) usergroup_id parameter in an edit_usergroup action in versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible...
- CVSS:
- 6.1
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.4
- Disclosed:
- May 15, 2012
CVE-2012-6622 on NVD →
WP Forum Server [forum-server] < 1.8
unknown
This WordPress Forum Server plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Upgrade the plugin.
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- Sep 13, 2011
WP Forum Server <= 1.6.5 - SQL Injection
critical
Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) search_max parameter in a search action to index.php, which is not properly handled by wpf.class.php, (2) id parameter in an editpost...
- CVSS:
- 9.8
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.6
- Disclosed:
- Feb 22, 2011
CVE-2011-1047 on NVD →
WP Forum Server [forum-server] < 1.6.6
unknown
[en] Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) search_max parameter in a search action to index.php, which is not properly handled by wpf.class.php, (2) id parameter in an edi...
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Feb 21, 2011
CVE-2011-1047 on NVD →
WP Forum Server [forum-server] < 1.7.1
unknown
The WP Forum Server WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database