Cross-Site Scripting in wpForo Plugin for WordPress
CVE-2019-19110
4.8MEDIUM
What is CVE-2019-19110?
The wpForo plugin for WordPress, specifically version 1.6.5, has a vulnerability that allows Cross-Site Scripting (XSS) via the 's' parameter in the admin panel at wp-admin/admin.php?page=wpforo-phrases. This vulnerability can potentially allow an attacker to inject malicious scripts into the application. If exploited, it may compromise the security of the affected WordPress site, leading to unauthorized actions and data exposure. Site administrators should take immediate measures to patch this vulnerability by updating to the latest version of the plugin or implementing appropriate security measures.