CVE-2012-6625: Vasthtml Forumpress
High severity, CVSS 7.5. EPSS: 4.9% chance of exploitation in the next 30 days.
SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action.
Affected products
- Vasthtml Forumpress: up to and including 1.7.4; version 1.0 only; version 1.1 only; version 1.2 only; version 1.3 only; version 1.4 only; …
Published 2014-01-16. Last modified 2026-06-16.