Known Vulnerabilities for WpForo Forum by Tomdever
Listed below are 10 of the newest known vulnerabilities associated with "WpForo Forum" by "Tomdever".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49769 json | Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49767 json | Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-42682 json | Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security... | Not Provided | 2026-06-01 | 2026-06-01 |
| CVE-2026-40798 json | Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-40767 json | Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-6248 json | The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is... | Not Provided | 2026-04-20 | 2026-04-21 |
| CVE-2026-5809 json | The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is... | Not Provided | 2026-04-11 | 2026-04-13 |
| CVE-2026-4666 json | The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EX... | Not Provided | 2026-04-17 | 2026-04-20 |
| CVE-2026-3666 json | The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. ... | Not Provided | 2026-04-04 | 2026-04-08 |
| CVE-2025-66070 json | Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control S... | Not Provided | 2025-12-18 | 2026-04-27 |