ForumWP – Forum & Discussion Board
ForumWP – Forum & Discussion Board has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 6 are fixed as of September 2026. Their average CVSS score is 6.9, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high. 2024 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (50%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Deserialization Of Untrusted Data.
Every one of the 6 issues recorded for ForumWP – Forum & Discussion Board has a vendor fix available, so running the current release closes all known holes.
5 independent researchers contributed these findings, most of them (2) reported by Peter Thaleikis. ForumWP – Forum & Discussion Board is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-54367ForumWP <= 2.1.0 - Unauthenticated PHP Object Injection
Read the full analysisVulnerability Records

ForumWP – Forum & Discussion Board
Author
Ultimate Member
ForumWP is a forum plugin which adds an online forum to your website. With ForumWP you can easily create forums and allow users to create topics and write replies. Features of the plugin include: Forum visibility Forum styling Topics list Topics search Replies list Sub-replies and sorting User login & registration Profile page Easy settings Manage forums, topics and replies Manage modules and email settings Read about all of the plugin’s features at ForumWP Documentation & Support Got a problem or need help with ForumWP? Head over to our documentation and perform a search of the knowledge base. If you can’t find a solution to your issue then you can create a topic on the support forum.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C