Vulnerability record · CVE-2023-2249 · published 9 June 2023
CVE-2023-2249: wpForo Forum plugin LFI, SSRF and PHAR deserialization via file_get_contents
Gvectors · Wpforo Forum
The wpForo Forum plugin for WordPress up to and including 2.1.7 passes attacker-controlled data to file_get_contents without proper verification, enabling local file inclusion, server-side request forgery and PHAR deserialization. Because a low-privileged authenticated user such as a subscriber can trigger it, any site with open registration or many low-trust accounts is exposed.
Description
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low-privilege authenticated access and a very high EPSS percentile make this a serious risk, though it is not in KEV and no public exploit is confirmed.
What it is
The wpForo Forum plugin for WordPress up to and including 2.1.7 passes attacker-controlled data to file_get_contents without proper verification, enabling local file inclusion, server-side request forgery and PHAR deserialization. Because a low-privileged authenticated user such as a subscriber can trigger it, any site with open registration or many low-trust accounts is exposed.
Impact
An attacker can read sensitive local files such as wp-config.php, make requests to internal services, and via PHAR deserialization potentially achieve remote code execution on the WordPress host.
Attack surface
Reached over the network through the vulnerable plugin code path; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates only low-privileged authentication is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is 0.60809 (99.1st percentile), indicating a high modeled likelihood of exploitation; references are patch commits and a third-party advisory only, with no public exploit tag.
What to do
- Update wpForo Forum to 2.1.8 or later, which contains the patch commits referenced in the advisory.
- If immediate patching is not possible, disable or remove the wpForo plugin until it can be updated.
- Restrict or audit subscriber-level account creation and review existing low-privilege accounts for abuse.
- Harden PHP configuration to reduce PHAR deserialization and file inclusion exposure, and limit outbound network access from the web server to internal services.
Detection
- Monitor web server and PHP logs for file_get_contents calls or requests referencing wp-config.php, phar:// wrappers, or unexpected local file paths.
- Alert on outbound HTTP requests from the WordPress host to internal RFC1918 addresses or loopback services.
- Review subscriber-role activity for unusual requests to wpForo endpoints, especially patterns suggesting file path or URL parameter manipulation.
- Check for unexpected file reads or new processes on the WordPress host that could indicate post-exploitation after deserialization.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-2249 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-2249), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.