plugin

Forumwp Vulnerabilities

12 known security issues reported for the Forumwp WordPress plugin. Most recent disclosed Jan 6, 2026.

1 critical 1 high 4 medium

Running Forumwp on your site? Check whether your installed version is affected.

Scan your site free

ForumWP – Forum &amp; Discussion Board [forumwp] < 2.1.7

unknown

[en] The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User's Display Name in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level acce...

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
Jan 6, 2026

CVE-2025-13746 on NVD →

ForumWP – Forum & Discussion Board <= 2.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name

medium

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User's Display Name in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access an...

CVSS:
6.4
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Jan 5, 2026

CVE-2025-13746 on NVD →

ForumWP – Forum &amp; Discussion Board [forumwp] <= 2.1.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in Ultimate Member ForumWP forumwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ForumWP: from n/a through <= 2.1.4.

Affected:
up to 2.1.4
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67474 on NVD →

ForumWP <= 2.1.4 - Missing Authorization

medium

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.1.4
Fixed in:
2.1.5
Disclosed:
Nov 21, 2025

CVE-2025-67474 on NVD →

ForumWP – Forum &amp; Discussion Board [forumwp] < 2.1.1

unknown

[en] Deserialization of Untrusted Data vulnerability in ForumWP ForumWP allows Object Injection.This issue affects ForumWP: from n/a through 2.1.0.

Affected:
up to 2.1.1
Fixed in:
2.1.1
Disclosed:
Dec 16, 2024

CVE-2024-54367 on NVD →

ForumWP <= 2.1.0 - Unauthenticated PHP Object Injection

critical

The ForumWP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an a...

CVSS:
9.8
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Dec 11, 2024

CVE-2024-54367 on NVD →

ForumWP – Forum &amp; Discussion Board [forumwp] < 2.1.3

unknown

[en] The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Dec 6, 2024

CVE-2024-11204 on NVD →

ForumWP – Forum &amp; Discussion Board [forumwp] < 2.1.3

unknown

[en] The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to inject arbitrar...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Dec 6, 2024

CVE-2024-10879 on NVD →

ForumWP – Forum & Discussion Board <= 2.1.2 - Reflected Cross-Site Scripting

medium

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
6.1
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Dec 5, 2024

CVE-2024-10879 on NVD →

ForumWP – Forum & Discussion Board <= 2.1.2 - Reflected Cross-Site Scripting via url Parameter

medium

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Dec 5, 2024

CVE-2024-11204 on NVD →

ForumWP – Forum & Discussion Board Plugin <= 2.0.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Privilege Escalation via Account Takeover

high

The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key. This makes it possible for authenticated a...

CVSS:
8.8
Affected:
up to 2.0.2
Fixed in:
2.1.0
Disclosed:
Sep 6, 2024

CVE-2024-8428 on NVD →

ForumWP – Forum &amp; Discussion Board [forumwp] < 2.1.0

unknown

[en] The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key. This makes it possible for authentica...

Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Sep 6, 2024

CVE-2024-8428 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database