Gvectors develops a focused line of WordPress community and commerce plugins—including WPDiscuz, WPForo, and WooDiscuz—that extend commenting, forum, and e-commerce functionality across a large installed base of WordPress sites. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the web-application and user-input handling demands of these community-facing extensions. The exposure recurs consistently across the plugin portfolio through application-layer weakness classes including cross-site scripting, cross-site request forgery, SQL injection, and authorization-bypass conditions that are characteristic of web plugins handling user-generated content and administrative functions. Defenders should prioritize patching these plugins given their visibility in WordPress deployment and their role in user interaction; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gvectors over time
Signals from CVEs in this vendor scope (70 CVEs).
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24186CRITICAL A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, includi | Aug 24, 2020 | 10.0 | 93 | NO | YES |
CVE-2023-2249HIGH The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is du | Jun 9, 2023 | 8.8 | 57 | NO | NO |
CVE-2020-13640CRITICAL A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoad | Jun 18, 2020 | 9.8 | 46 | NO | YES |
CVE-2026-22192CRITICAL Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipula | Mar 13, 2026 | 9.9 | 36 | NO | NO |
CVE-2026-22199HIGH Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitra | Mar 13, 2026 | 7.5 | 31 | NO | NO |
CVE-2021-24406MEDIUM The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login | Jul 6, 2021 | 6.1 | 31 | NO | YES |
CVE-2026-28562CRITICAL wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted ide | Feb 28, 2026 | 9.8 | 30 | NO | NO |
CVE-2024-9488CRITICAL The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the us | Oct 25, 2024 | 9.8 | 30 | NO | NO |
CVE-2018-16613CRITICAL An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator wi | Jun 19, 2019 | 9.8 | 30 | NO | NO |
CVE-2023-2309MEDIUM The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability. | Jul 24, 2023 | 6.1 | 29 | NO | YES |
Signals from CVEs in this vendor scope (70 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gvectors.
Media articles that mention a CVE ID that affects a product developed by Gvectors — matched by CVE ID, not by vendor name.