wpForo Forum
by Tomdever · Uncategorized
Number one WordPress forum plugin with AI features. Full-fledged forum solution with modern forum design. Community builder WordPress forum plugin.
96 health vs 56 average across 16,378 Uncategorized plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
19.3K
now · peak 68.4K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
24
releases in the last 12 months
2mo ago
latest release · v3.1.2
134
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 49% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “20K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2016-08-27 · 1,473 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ Ricsca25mo ago
The best forum for WordPress
Read on wp.org ↗ - ★★★★★ kuyawing6mo ago
I’ve been using this forum plugin for 2 years now. It is simply the best forum software out there. The support forum is also amazing.There’s no other WordPress forum out there that is better than wpforo.
Read on wp.org ↗ - ★★★★★ abigaildcd7mo ago
I really like this plugin. The learning curve is bearable and the support on their forum is excellent. The provided layout are great and if you must customizing them is not that hard. Read the documentation it actually will help you and if like me you get stuck on something because you don’t understand go to the user forum. My issue was so simple to solve I slapped my forehead to remind myself that sometimes even my own stupidity has no limits. The plugin is excellent. Thank you to the developers to really thinking this through.
Read on wp.org ↗ - ★★★★★ bbrian0177mo ago
wpForo has exceeded my expectations as a WordPress forum plugin. The feature set is robust, well thought out, and powerful without being overwhelming. Most importantly, it worked seamlessly with my existing WordPress setup and integrated perfectly with my Divi theme right out of the box—no hacks or workarounds required. The plugin also tied cleanly into my pre-existing WordPress database, which made deployment smooth and worry-free. Performance has been solid, and the forum structure is flexible enough to support both simple discussions and more advanced community use cases. What really sets wpForo apart, though, is the support. I ran into two CSS issues that were beyond my skill level—I’m not a coder—and the support I received through the forums was excellent. The responses were friendly, accurate, and genuinely helpful, and the turnaround time was impressively fast. It’s rare to find a plugin that combines strong features, smooth theme compatibility, and responsive, high-quality support. wpForo delivers on all three. Highly recommended.
Read on wp.org ↗ - ★★★★★ Martin Sauter9mo ago
wpForo is a feature-rich, highly configurable forum solution for free. Highly recommended!
Read on wp.org ↗ - ★★★★★ fufy1.1y ago
This free plugin totally gives a lot. It provides everything needed to build a forum, one plugin and that’s all. Best plugin ever. This topic was modified 12 months ago by fufy.
Read on wp.org ↗ - ★★★★★ geddi21.1y ago
Any idea how to switch to German? Unfortunately, all my efforts have failed. I’ve placed the files wpforo-de_DE.po and wpforo-de_DE.mo in /languages/plugins/ – with no success. Switching to “Deutsch-Sie” or “Deutsch” didn’t help either. The author documentation page for translating WPForo shows “In progress” with a date of 2022.This all seems a bit too casual for a serious forum installation. So I guess I’ll have to look for something else. ———————– Irgendeine Idee, wie man auf Deutsch umstellt? Leider scheitern alle meine Bemühungen. Ich habe die Dateien wpforo-de_DE.po und wpforo-de_DE.mo in /languages/plugins/ abgelegt – ohne Erfolg. Auch das Umstellen auf “Deutsch-Sie” oder “Deutsch” halfen nicht. Die Autorendokumentationsseite zur Übersetzung von WPForo zeigt „In Bearbeitung“ mit einem Datum aus dem Jahr 2022 an.Das alles scheint mir etwas zu lässig für eine seriöse Foruminstallation. Also muss ich mich wohl nach etwas anderem umsehen.
Read on wp.org ↗ - ★★★★★ mikesafh1.2y ago
I’m running this plugin on one, soon to be maybe two, non-profit websites, and needed a reasonable option to not have to keep using Facebook when people (especially those that like me don’t like Facebook) on the website wanted forum functionality. This fits the bill, and support for it has been outstanding when needed. There are so many features I haven’t even looked at too, but haven’t had to. Yet.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 3.1.2 Security: Fixed Stored XSS vulnerability in profile fields Security: Fixed IDOR vulnerability in AI Chat messaging Security: Fixed Mass Assignment vulnerability with privilege escalation via profile fields Added: Ultimat 3.1.2
- — Version 3.1.1 Security: Fixed Broken Authentication vulnerability allowing administrator email mutation Security: Fixed PHP Object Injection vulnerability via widget AJAX handlers 3.1.1
- — Version 3.1.0 Security: Fixed vulnerability issue in the Revisions module Security: Fixed vulnerability issue in Gutenberg block renderers New: Tools – Email Queue Tab, email notifications now sent asynchronously with automatic fallba 3.1.0
- — Version 3.0.9 Fixed: AI Task “Topic Tag Manager” now runs asynchronously to avoid blocking topic creation Fixed: AI Content Moderation now correctly exempts admins and moderators from spam detection Fixed: AI Logs timezone display – t 3.0.9
- — Version 3.0.8 Fixed: AI Chat WordPress content citations not displaying as clickable links Updated: New phrases to wpForo Phrase System Updated: Translation template (wpforo.pot) with AI feature phrases 3.0.8
- — Version 3.0.7 Security: Fixed usergroup privilege escalation vulnerability during registration New: WordPress Indexing now has its own dedicated admin tab Fixed: AI Chatbot now respects “Bot Reply Unapproved” setting correctly Fixed: 3.0.7
Known vulnerabilities
via Wordfence Intelligence48 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-07-20 CVE-2026-12696 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.1 Patched in 3.1.2
- Medium · 4.3 wpForo Forum <= 3.1.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Chat Message Deletion ↗2026-07-16 CVE-2026-12697 Authorization Bypass Through User-Controlled Key Affects <= 3.1.1 Patched in 3.1.2
- Medium · 6.4 wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field ↗2026-07-15 CVE-2026-15021 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.1 Patched in 3.1.2
- 2026-06-26 CVE-2026-57636 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.0.9 Patched in 3.1.0
- Medium · 5.3 wpForo Forum <= 3.1.0 - Missing Authorization ↗
- Medium · 5.3 wpForo Forum <= 3.0.6 - Missing Authorization ↗
- 2026-05-07 CVE-2026-40798 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.0.4 Patched in 3.0.5
- Medium · 5.3 wpForo Forum < 3.0.2 - Missing Authorization ↗
- 2026-04-20 CVE-2026-6248 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.0.5 Patched in 3.0.6
- High · 8.8 wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body ↗2026-04-03 CVE-2026-3666 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.4.16 Patched in 2.4.17
- 2026-02-18 CVE-2026-1581 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.4.14 Patched in 2.4.15
- 2025-12-13 CVE-2025-13126 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.4.12 Patched in 2.4.13
- Medium · 5.3 wpForo Forum <= 2.4.10 - Missing Authorization ↗
- 2025-10-31 CVE-2025-11740 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.4.9 Patched in 2.4.10
- 2025-10-24 CVE-2025-4203 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.4.8 Patched in 2.4.9
- 2025-09-03 CVE-2025-58597 Authorization Bypass Through User-Controlled Key Affects <= 2.4.6 Patched in 2.4.7
- Medium · 5.4 wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar ↗2025-07-09 CVE-2025-4406 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.4.5 Patched in 2.4.6
- 2024-08-16 CVE-2024-43289 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.3.4 Patched in 2.3.5
- 2024-08-16 CVE-2024-43288 Authorization Bypass Through User-Controlled Key Affects <= 2.3.4 Patched in 2.3.5
- 2024-05-31 CVE-2024-3200 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.3.3 Patched in 2.3.4
- 2023-11-20 CVE-2023-47872 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.3 Patched in 2.2.4
- Medium · 4.3 wpForo Forum <= 2.2.5 - Missing Authorization ↗
- 2023-07-03 CVE-2023-2309 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.1.8 Patched in 2.1.9
- 2023-06-01 CVE-2023-2249 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 2.1.7 Patched in 2.1.8
- 2022-12-07 CVE-2022-38055 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 2.0.9 Patched in 2.1.0
- 2022-11-26 CVE-2022-40206 Authorization Bypass Through User-Controlled Key Affects <= 2.0.5 Patched in 2.0.6
- 2022-11-09 CVE-2022-40200 Unrestricted Upload of File with Dangerous Type Affects <= 2.0.9 Patched in 2.1.0
- 2022-09-26 CVE-2022-40205 Authorization Bypass Through User-Controlled Key Affects <= 2.0.5 Patched in 2.0.6
- Medium · 6.1 wpForo Forum <= 1.9.6 - Open Redirect ↗2021-06-14 CVE-2021-24406 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 1.9.6 Patched in 1.9.7
- 2020-05-04 CVE-2019-19111 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.6.5 Patched in 1.7.0
- 2020-05-04 CVE-2019-19112 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.6.5 Patched in 1.7.0
- 2020-05-04 CVE-2019-19110 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.6.5 Patched in 1.7.0
- Critical · 9.8 wpForo < = 1.5.1 - Privilege Escalation ↗
- 2018-06-01 CVE-2018-11709 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.4.12 Patched in 1.4.12
- Critical · 9.8 wpForo Forum <= 1.4.12 - SQL Injection ↗2018-05-27 CVE-2018-11515 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.4.12 Patched in 1.4.13
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 35 languages, 4 at 90% or more
Plus 11 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Asgaros Forum 10K+ installs · 4.7★ · 3 shared tags A -
Forumax – AI Powered Advanced Community Forum Plugin 600+ installs · 4.6★ · 3 shared tags A -
Ultimate Member – ForumWP forum integration 500+ installs · 2.9★ · 3 shared tags D -
bbPress Voting 500+ installs · 4.3★ · 3 shared tags A - V Vanilla Forums 100+ installs · 3.3★ · 3 shared tags F
- B bbPress Integration 70+ installs · 3.6★ · 3 shared tags D
Embed this report card
Drop a live Pulse card for wpForo Forum into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wpforo" width="480" height="300" style="border:0" loading="lazy" title="wpForo Forum — Plugin Pulse"></iframe> wpForo Forum: 20K+ active installs, 4.7★ (390 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/wpforo