Ultimatemember

Forumwp

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 06.01.2026 03:21:41
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User's Display Name in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it...

  • EPSS 0.05%
  • Veröffentlicht 09.12.2025 14:13:57
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Missing Authorization vulnerability in Ultimate Member ForumWP forumwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ForumWP: from n/a through <= 2.1.4.

  • EPSS 0.73%
  • Veröffentlicht 16.12.2024 15:15:10
  • Zuletzt bearbeitet 01.04.2026 16:21:09

Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a through <= 2.1.0.

  • EPSS 1.25%
  • Veröffentlicht 06.12.2024 09:15:05
  • Zuletzt bearbeitet 08.04.2026 17:17:34

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.2. This m...

  • EPSS 1.25%
  • Veröffentlicht 06.12.2024 09:15:05
  • Zuletzt bearbeitet 08.04.2026 19:19:36

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it ...

  • EPSS 0.2%
  • Veröffentlicht 06.09.2024 14:15:13
  • Zuletzt bearbeitet 08.04.2026 19:22:24

The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'us...