CVE Alert: CVE-2026-6248 - tomdever - wpForo Forum - RedPacket Security

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws:

RedPacket Security
CVE Alert: CVE-2026-5809 - tomdever - wpForo Forum - RedPacket Security

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw:

RedPacket Security
CVE Alert: CVE-2026-3666 - tomdever - wpForo Forum - RedPacket Security

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file

RedPacket Security
CVE Alert: CVE-2026-1581 - tomdever - wpForo Forum - RedPacket Security

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to

RedPacket Security
CVE Alert: CVE-2026-0910 - tomdever - wpForo Forum - RedPacket Security

The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted

RedPacket Security
CVE Alert: CVE-2025-13126 - tomdever - wpForo Forum - RedPacket Security

The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and

RedPacket Security
CVE Alert: CVE-2025-4203 - tomdever - wpForo Forum - RedPacket Security

The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and

RedPacket Security