Content Spoofing Vulnerability in wpForo Forum
CVE-2022-38055

4.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
21 June 2024

Summary

The vulnerability in gVectors Team's wpForo Forum arises from improper handling of script-related HTML tags, allowing attackers to inject malicious scripts into web pages. This can lead to content spoofing where the malicious content displayed to users may compromise their interaction with the forum. Users running any version of wpForo Forum up to 2.0.9 are particularly at risk, as this flaw exploits the plugin's inability to properly neutralize certain input, thereby creating opportunities for various web-based attacks. Securing against this vulnerability requires timely updates and careful validation of input data.

Affected Version(s)

wpForo Forum <= 2.0.9

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.