---
id: CVE-2025-4203
title: >-
  The wpForo Forum plugin for WordPress is vulnerable to error‐based or
  time-based SQL Injection via the get_members() function in all versions up to,
  and including, 2.4.8 due to missing integer validation on the 'offset' and
  'row_count' p…
summary: >-
  The wpForo Forum plugin for WordPress is vulnerable to error‐based or
  time-based SQL Injection via the get_members() function in all versions up to,
  and including, 2.4.8 due to missing integer validation on the 'offset' and
  'row_count' p…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-89
published: '2025-10-25'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-4203'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.5/classes/Members.php#L1557
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpforo/tags/2.4.9/classes/Members.php#L1557
    label: security@wordfence.com
  - url: 'https://wordpress.org/plugins/wpforo/#developers'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/bc406e8a-c4eb-45c3-a53c-37644e0dabfa?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00369
epssPercentile: 0.28689
ingestedAt: '2026-10-08T11:31:27.585Z'
---

## Overview

The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x’s grammar allows a 'PROCEDURE ANALYSE' clause immediately after a LIMIT clause. Unauthenticated attackers controlling 'row_count' can append a stored‐procedure call, enabling error‐based or time‐based blind SQL injection that can be used to extract sensitive information from the database.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
