PHP Object Injection Vulnerability in wpForo Forum Plugin by WordPress
CVE-2026-80513

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-80513?

The wpForo Forum plugin for WordPress, prior to version 3.1.6, is vulnerable to PHP Object Injection due to inadequate restrictions on deserialized user-supplied profile field values. This loophole enables authenticated users with Subscriber-level access or higher to instantiate arbitrary classes. Although the wpForo plugin itself does not possess a direct privilege escalation chain, its integration with other vulnerable plugins could result in serious security threats, including remote code execution, unauthorized file access, and SQL injection attacks. This vulnerability is an incomplete fix of a previous issue tracked in CVE-2026-49769.

Affected Version(s)

wpForo Forum 0 < 3.1.6

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sai Praneeth Koti
WPScan
.