๐Ÿ” CVE Alert

CVE-2026-80513

UNKNOWN 0.0

wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before 3.1.6 itself; if one is present via another installed wpForo Forum WordPress plugin before 3.1.6 or , this could lead to remote code execution, arbitrary file operations, or SQL injection. This is an incomplete fix of CVE-2026-49769.

Vendor unknown
Product wpforo forum
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wpforo forum

Be the first to know when new unknown vulnerabilities affecting unknown wpforo forum are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / wpForo Forum
0 < 3.1.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/09c9b9e7-c178-4f05-80d8-d4d77b7c5050/

Credits

Sai Praneeth Koti WPScan