Cross-Site Scripting Vulnerability in ForumPress WP Forum Server Plugin by WordPress
CVE-2012-6623
Currently unrated
What is CVE-2012-6623?
The ForumPress WP Forum Server plugin for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability. This issue arises from improper validation of the groupid parameter in the addforum action, allowing remote attackers to inject arbitrary web scripts or HTML. To mitigate the risk, users of versions prior to 1.7.5 are strongly advised to update their installations promptly.