CVE-2026-80513
wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before 3.1.6 itself; if one is present via another installed wpForo Forum WordPress plugin before 3.1.6 or , this could lead to remote code execution, arbitrary file operations, or SQL injection. This is an incomplete fix of CVE-2026-49769.
| Vendor | unknown |
| Product | wpforo forum |
| Published | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpforo forum
Be the first to know when new unknown vulnerabilities affecting unknown wpforo forum are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / wpForo Forum
0 < 3.1.6
References
Credits
Sai Praneeth Koti WPScan