Black Friday Deals 40% OFF

Days
Hours
Minutes

Input validation vulnerability in wpForo Forum 2.4.9

The wpForo Forum plugin for WordPress has a security issue called SQL Injection that affects all versions up to 2.4.9. This happens because the plugin does not properly protect user input and does not properly prepare the SQL query. As a result, people with Subscriber-level access or higher can add their own queries to the existing ones, which could potentially access private information from the database.

Detected in:

wpForo Forum fixed vulnerable versions: >= * <= 2.4.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.