WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Simple:Press Forum

The most versatile and feature-rich forum plugin for WordPress. Create unlimited forums with awesome features directly in your WordPress site.

10Reported vulnerabilities
9.8Highest CVSS score
6.11.14Latest version
300+Active installs

What to do now

Update Simple:Press Forum to 6.11.6 or later. 10 of these have a fixed version available. Updating resolves them.

Plugin last updated: January 29, 2026 / Tested up to WordPress: 6.8.8 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2020-36706 Critical 9.8 1.8% Before 6.6.1 6.6.1 October 20, 2023
CVE-2024-10483 High 7.1 0.4% Before 6.10.11 6.10.11 February 26, 2025
CVE-2022-4030 High 8.1 1.6% 6.8.0 and earlier 6.8.1 November 29, 2022
CVE-2024-12409 Medium 6.1 0.3% Before 6.10.12 6.10.12 January 30, 2025
CVE-2022-4028 Medium 5.4 0.5% 6.8.0 and earlier 6.8.1 November 29, 2022
CVE-2022-4027 Medium 5.4 0.6% 6.8.0 and earlier 6.8.1 November 29, 2022
CVE-2025-31386 Medium 5.3 0.3% 6.11.5 and earlier 6.11.6 March 31, 2025
CVE-2022-4031 Medium 4.9 0.7% 6.8.0 and earlier 6.8.1 November 29, 2022
CVE-2022-4029 Medium 4.7 0.6% 6.8.0 and earlier 6.8.1 November 29, 2022
CVE-2024-13518 Medium 4.3 0.2% 6.10.11 and earlier 6.10.13 March 1, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.