
ForumWP – Forum & Discussion Board Security & Risk Analysis
wordpress.org/plugins/forumwpAdd a forum to your website with ForumWP.
Is ForumWP – Forum & Discussion Board Safe to Use in 2026?
Generally Safe
Score 86/100ForumWP – Forum & Discussion Board has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "forumwp" v2.1.8 exhibits a mixed security posture. While it demonstrates strong practices in output escaping (99% proper) and uses prepared statements for a significant portion of its SQL queries (68%), there are notable areas of concern. The substantial attack surface, particularly the 60 unprotected AJAX handlers, presents a significant risk. Taint analysis reveals two high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited if these flows are triggered by malicious input. The plugin's history of six known CVEs, including one critical and one high severity, is a major red flag. Although currently no CVEs are unpatched, the pattern of past vulnerabilities like missing authorization, deserialization, and XSS suggests recurring security weaknesses that require careful attention. The plugin has demonstrated strengths in output handling and SQL query preparation, but the large number of unprotected entry points and past critical vulnerabilities necessitate caution.
Key Concerns
- 60 unprotected AJAX handlers
- 2 high severity taint flows
- 1 critical CVE in history
- 1 high severity CVE in history
- Missing nonce checks on 60 AJAX handlers
- 3 flows with unsanitized paths
ForumWP – Forum & Discussion Board Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
ForumWP – Forum & Discussion Board <= 2.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name
ForumWP <= 2.1.4 - Missing Authorization
ForumWP <= 2.1.0 - Unauthenticated PHP Object Injection
ForumWP – Forum & Discussion Board <= 2.1.2 - Reflected Cross-Site Scripting
ForumWP – Forum & Discussion Board <= 2.1.2 - Reflected Cross-Site Scripting via url Parameter
ForumWP – Forum & Discussion Board Plugin <= 2.0.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Privilege Escalation via Account Takeover
ForumWP – Forum & Discussion Board Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ForumWP – Forum & Discussion Board Attack Surface
AJAX Handlers 65
Shortcodes 12
WordPress Hooks 164
Maintenance & Trust
ForumWP – Forum & Discussion Board Maintenance & Trust
Maintenance Signals
Community Trust
ForumWP – Forum & Discussion Board Alternatives
bbPress auto subscribe for new topics and replies
bbpress-auto-subscribe-for-new-topics-and-replies
Automatically checks the subscription checkbox for new bbpress topics or bbpress replies and saves the last state via ajax for each user and for new t …
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar
Setup paid membership, accept payment, sell subscription & digital product, paywall, create login & registration form, user profile & member directory
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
user-registration
Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
profile-builder
Powerful user profile plugin to create front-end user registration forms, login & user profile forms. Includes user role editor & content restriction.
ForumWP – Forum & Discussion Board Developer Profile
3 plugins · 202K total installs
How We Detect ForumWP – Forum & Discussion Board
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/forumwp/assets/admin/css/common.css/wp-content/plugins/forumwp/assets/admin/css/forms.css/wp-content/plugins/forumwp/assets/admin/js/common.js/wp-content/plugins/forumwp/assets/admin/js/forms.js/wp-content/plugins/forumwp/assets/admin/js/global.js/wp-content/plugins/forumwp/assets/admin/js/global.js/wp-content/plugins/forumwp/assets/admin/js/common.js/wp-content/plugins/forumwp/assets/admin/js/forms.jsforumwp/assets/admin/css/common.css?ver=forumwp/assets/admin/css/forms.css?ver=forumwp/assets/admin/js/common.js?ver=forumwp/assets/admin/js/forms.js?ver=forumwp/assets/admin/js/global.js?ver=HTML / DOM Fingerprints
fmwp-adminfmwp-formsfmwp-common-admindata-nonce=\"fmwp-backend-nonce\"fmwp_admin_data