Discussion Board – WordPress Forum Plugin [wp-discussion-board] <= 2.5.7 (unfixed)
unknown
[en] Missing Authorization vulnerability in Marketing Fire Discussion Board wp-discussion-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Discussion Board: from n/a through <= 2.5.7.
- Affected:
- up to 2.5.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2025
CVE-2025-69023 on NVD →
Discussion Board <= 2.5.7 - Missing Authorization
medium
The Discussion Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.7. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.5.7
- Fixed in:
- 2.5.8
- Disclosed:
- Dec 28, 2025
CVE-2025-69023 on NVD →
Discussion Board – WordPress Forum Plugin <= 2.5.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
medium
The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.5.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible f...
- CVSS:
- 6.3
- Affected:
- up to 2.5.5
- Fixed in:
- 2.5.6
- Disclosed:
- Oct 24, 2025
CVE-2025-8483 on NVD →
Discussion Board – WordPress Forum Plugin [wp-discussion-board] < 2.4.9
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discussion Board allows Content Spoofing, Cross-Site Scripting (XSS).This issue affects Discussion Board: from n/a through 2.4.8.
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- Jun 4, 2024
CVE-2023-39161 on NVD →
Discussion Board <= 2.4.8 - Authenticated (Subscriber+) Content Injection
medium
The Discussion Board plugin for WordPress is vulnerable to Content Injection in versions up to, and including, 2.4.8 via the discussion feature. This vulnerability makes it possible for authenticated attackers, subscribers and higher, to inject new content onto the website, through the manipulation of posts to create n...
- CVSS:
- 5.4
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.9
- Disclosed:
- Jul 26, 2023
CVE-2023-39161 on NVD →
Discussion Board – WordPress Forum Plugin [wp-discussion-board] < 2.5.6
unknown
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
CVE-2025-8483 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database