PHP Object Injection Vulnerability in wpForo Forum Plugin by WordPress
CVE-2026-80513
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 24 September 2026
Badges
What is CVE-2026-80513?
The wpForo Forum plugin for WordPress, prior to version 3.1.6, is vulnerable to PHP Object Injection due to inadequate restrictions on deserialized user-supplied profile field values. This loophole enables authenticated users with Subscriber-level access or higher to instantiate arbitrary classes. Although the wpForo plugin itself does not possess a direct privilege escalation chain, its integration with other vulnerable plugins could result in serious security threats, including remote code execution, unauthorized file access, and SQL injection attacks. This vulnerability is an incomplete fix of a previous issue tracked in CVE-2026-49769.
Affected Version(s)
wpForo Forum 0 < 3.1.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.