Cross-Site Scripting in wpForo Plugin for WordPress
CVE-2019-19110
4.8MEDIUM
Summary
The wpForo plugin for WordPress, specifically version 1.6.5, has a vulnerability that allows Cross-Site Scripting (XSS) via the 's' parameter in the admin panel at wp-admin/admin.php?page=wpforo-phrases. This vulnerability can potentially allow an attacker to inject malicious scripts into the application. If exploited, it may compromise the security of the affected WordPress site, leading to unauthorized actions and data exposure. Site administrators should take immediate measures to patch this vulnerability by updating to the latest version of the plugin or implementing appropriate security measures.
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved