
WP Forum Server Security & Risk Analysis
wordpress.org/plugins/forum-serverThis Wordpress plugin is a complete forum system for your wordpress blog.
Is WP Forum Server Safe to Use in 2026?
Critical Risk — Avoid
Score 24/100WP Forum Server is critically unsafe with 6 known CVEs, 2 still unpatched. Avoid in production.
The 'forum-server' plugin v1.8.2 exhibits a concerning security posture, heavily outweighed by significant risks despite a seemingly limited attack surface. The static analysis reveals a critical flaw in the use of `unserialize`, which is a known vector for remote code execution if used with untrusted input. Furthermore, the taint analysis indicates a high prevalence of unsanitized paths (100% of analyzed flows), with 7 flows marked as high severity, suggesting potential data leakage or manipulation vulnerabilities. The complete lack of nonce checks and capability checks on any entry points, combined with a very low percentage of properly escaped output (1%), amplifies these risks, making it highly susceptible to various injection attacks.
The vulnerability history is also alarming. Six known CVEs, with two still unpatched, including one critical and two high-severity vulnerabilities, demonstrate a recurring pattern of security weaknesses. The common vulnerability types (CSRF, SQL Injection, XSS) align with the observed code signals (lack of sanitization, raw SQL, unescaped output). The recent nature of the last vulnerability further suggests ongoing security issues. While the plugin reports no external HTTP requests, this offers minimal mitigation against the severe internal code and historical vulnerabilities. In conclusion, this plugin presents a high risk due to its exploitable code patterns, extensive unsanitized data flows, and a history of critical and unpatched vulnerabilities, indicating a lack of robust security development practices.
Key Concerns
- Unpatched Critical CVE (x1)
- Unpatched High CVE (x2)
- High severity taint flows (x7)
- Dangerous function: unserialize
- Low percentage of prepared statements (12%)
- Very low percentage of properly escaped output (1%)
- No nonce checks
- No capability checks
- 14 flows with unsanitized paths
WP Forum Server Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
WP Forum Server <= 1.8.2 - Cross-Site Request Forgery
WP Forum Server <= 1.8.2 - Authenticated (Administrator+) SQL Injection
WP Forum Server <= 1.7.3 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Forum Server < 1.7.5 - Cross-Site Scripting
WP Forum Server < 1.7.4 - SQL Injection
WP Forum Server <= 1.6.5 - SQL Injection
WP Forum Server Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Forum Server Attack Surface
WordPress Hooks 14
Maintenance & Trust
WP Forum Server Maintenance & Trust
Maintenance Signals
Community Trust
WP Forum Server Alternatives
wpForo Forum
wpforo
Number one WordPress forum plugin. Full-fledged forum solution with modern and responsive forum design. Community builder WordPress forum plugin.
bbp style pack
bbp-style-pack
For bbPress - Lets you style bbPress, and add display features
bbPress Notify (No-Spam)
bbpress-notify-nospam
Powerful, customizable email notifications for bbPress and BuddyBoss forums — without the spam.
Private groups
bbp-private-groups
For bbPress - Creates private forum groups
bbPress WP Tweaks
bbpress-wp-tweaks
Adds bbPress forum specific sidebar, wrapper, widgets, user columns, login links and other tweaks.
WP Forum Server Developer Profile
1 plugin · 100 total installs
How We Detect WP Forum Server
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/forum-server/css/wpf-style.css/wp-content/plugins/forum-server/js/wpf.js/wp-content/plugins/forum-server/images/forum-server-logo.png/wp-content/plugins/forum-server/images/user.png/wp-content/plugins/forum-server/js/wpf.jsforum-server/css/wpf-style.css?ver=forum-server/js/wpf.js?ver=HTML / DOM Fingerprints
wpf-wrapwpf-contentwpf-postwpf-replywpf-avatarwpf-authorwpf-metawpf-subject+5 more<!-- START WP FORUM SERVER --><!-- END WP FORUM SERVER -->data-wpf-forum-iddata-wpf-post-iddata-wpf-user-idwpf_ajax_urlwpf_settings/wp-json/forum-server/v1/posts/wp-json/forum-server/v1/users[wpf-list-forums][wpf-recent-posts][wpf-user-profile][wpf-search]