Cross-Site Scripting in wpForo Plugin for WordPress
CVE-2019-19110

4.8MEDIUM

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
15 June 2020

Summary

The wpForo plugin for WordPress, specifically version 1.6.5, has a vulnerability that allows Cross-Site Scripting (XSS) via the 's' parameter in the admin panel at wp-admin/admin.php?page=wpforo-phrases. This vulnerability can potentially allow an attacker to inject malicious scripts into the application. If exploited, it may compromise the security of the affected WordPress site, leading to unauthorized actions and data exposure. Site administrators should take immediate measures to patch this vulnerability by updating to the latest version of the plugin or implementing appropriate security measures.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.