🔐 CVE Alert

CVE-2025-4203

HIGH 7.5

wpForo Forum <= 2.4.8 - Unauthenticated SQL Injection via get_members Function

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x’s grammar allows a 'PROCEDURE ANALYSE' clause immediately after a LIMIT clause. Unauthenticated attackers controlling 'row_count' can append a stored‐procedure call, enabling error‐based or time‐based blind SQL injection that can be used to extract sensitive information from the database.

CWE CWE-89
Vendor tomdever
Product wpforo forum
Published Oct 25, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for tomdever wpforo forum

Be the first to know when new high vulnerabilities affecting tomdever wpforo forum are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

tomdever / wpForo Forum
0 ≤ 2.4.8

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/bc406e8a-c4eb-45c3-a53c-37644e0dabfa?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.5/classes/Members.php#L1557 wordpress.org: https://wordpress.org/plugins/wpforo/#developers plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.9/classes/Members.php#L1557

Credits

Michael Mazzolini