← Vulnerability feed

Vulnerability record · CVE-2023-2249 · published 9 June 2023

CVE-2023-2249: wpForo Forum plugin LFI, SSRF and PHAR deserialization via file_get_contents

Gvectors · Wpforo Forum

The wpForo Forum plugin for WordPress up to and including 2.1.7 passes attacker-controlled data to file_get_contents without proper verification, enabling local file inclusion, server-side request forgery and PHAR deserialization. Because a low-privileged authenticated user such as a subscriber can trigger it, any site with open registration or many low-trust accounts is exposed.

8.8 CVSS 3.1 High EPSS 61% · top 0.9% CWE-98 · PHP remote file inclusionCWE-829 · Inclusion from untrusted sphere
8.8CVSS 3.1 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.8 with low-privilege authenticated access and a very high EPSS percentile make this a serious risk, though it is not in KEV and no public exploit is confirmed.

What it is

The wpForo Forum plugin for WordPress up to and including 2.1.7 passes attacker-controlled data to file_get_contents without proper verification, enabling local file inclusion, server-side request forgery and PHAR deserialization. Because a low-privileged authenticated user such as a subscriber can trigger it, any site with open registration or many low-trust accounts is exposed.

Impact

An attacker can read sensitive local files such as wp-config.php, make requests to internal services, and via PHAR deserialization potentially achieve remote code execution on the WordPress host.

Attack surface

Reached over the network through the vulnerable plugin code path; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates only low-privileged authentication is required and no user interaction is needed.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is 0.60809 (99.1st percentile), indicating a high modeled likelihood of exploitation; references are patch commits and a third-party advisory only, with no public exploit tag.

What to do

  • Update wpForo Forum to 2.1.8 or later, which contains the patch commits referenced in the advisory.
  • If immediate patching is not possible, disable or remove the wpForo plugin until it can be updated.
  • Restrict or audit subscriber-level account creation and review existing low-privilege accounts for abuse.
  • Harden PHP configuration to reduce PHAR deserialization and file inclusion exposure, and limit outbound network access from the web server to internal services.

Detection

  • Monitor web server and PHP logs for file_get_contents calls or requests referencing wp-config.php, phar:// wrappers, or unexpected local file paths.
  • Alert on outbound HTTP requests from the WordPress host to internal RFC1918 addresses or loopback services.
  • Review subscriber-role activity for unusual requests to wpForo endpoints, especially patterns suggesting file path or URL parameter manipulation.
  • Check for unexpected file reads or new processes on the WordPress host that could indicate post-exploitation after deserialization.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-2249 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47868Gvectors wpforo forum improper privilege management vulnerabilityImproper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.…EPSS 0.48%9.8CVE-2018-16613Gvectors wpforo forum vulnerabilityAn issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privileg…EPSS 2.7%8.8CVE-2026-28562Gvectors wpforo forum sql injection vulnerabilitywpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql…EPSS 0.50%8.8CVE-2023-47870Gvectors wpforo forum cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Access…EPSS 0.27%8.8CVE-2022-40200Gvectors wpforo forum unrestricted file upload vulnerabilityAuth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.EPSS 0.96%8.8CVE-2022-40192Gvectors wpforo forum cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.EPSS 0.48%8.8CVE-2022-38144Gvectors wpforo forum cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.EPSS 0.51%8.1CVE-2024-43288Gvectors wpforo forum insecure direct object reference vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2023-2249), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.