Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gvectors

First CVE: May 28, 2018Active for: 8 yearsTotal CVEs: 70
40.6
VTI Score
High

Gvectors develops a focused line of WordPress community and commerce plugins—including WPDiscuz, WPForo, and WooDiscuz—that extend commenting, forum, and e-commerce functionality across a large installed base of WordPress sites. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the web-application and user-input handling demands of these community-facing extensions. The exposure recurs consistently across the plugin portfolio through application-layer weakness classes including cross-site scripting, cross-site request forgery, SQL injection, and authorization-bypass conditions that are characteristic of web plugins handling user-generated content and administrative functions. Defenders should prioritize patching these plugins given their visibility in WordPress deployment and their role in user interaction; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
70
Total CVEs
More Total CVEs than 99% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gvectors over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 2018
8 years ago
Most Recent CVE
Mar 13, 2026
133 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (70 CVEs).

70 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-24186CRITICAL
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, includi
Aug 24, 202010.093NOYES
CVE-2023-2249HIGH
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is du
Jun 9, 20238.857NONO
CVE-2020-13640CRITICAL
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoad
Jun 18, 20209.846NOYES
CVE-2026-22192CRITICAL
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipula
Mar 13, 20269.936NONO
CVE-2026-22199HIGH
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitra
Mar 13, 20267.531NONO
CVE-2021-24406MEDIUM
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login
Jul 6, 20216.131NOYES
CVE-2026-28562CRITICAL
wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted ide
Feb 28, 20269.830NONO
CVE-2024-9488CRITICAL
The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the us
Oct 25, 20249.830NONO
CVE-2018-16613CRITICAL
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator wi
Jun 19, 20199.830NONO
CVE-2023-2309MEDIUM
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.
Jul 24, 20236.129NOYES
View all 70 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products70 CVEs
64%
24%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network69 (98.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.4%)
Attack Complexity
Low70 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None41 (58.6%)
Unknown0 (0.0%)
Required29 (41.4%)
Privileges Required
Low21 (30.0%)
High9 (12.9%)
None40 (57.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (70 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.4% of CVEs· 97th percentile
Nuclei
5 CVEs
7.1% of CVEs· 96th percentile
ExploitDB
1 CVE
1.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gvectors.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gvectors — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gvectors's Products

View all 5 CNAs →

Top CWEs