Stored Cross-Site Scripting Vulnerability in ForumWP Plugin for WordPress
CVE-2025-13746
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 January 2026
What is CVE-2025-13746?
The ForumWP β Forum & Discussion Board plugin for WordPress is subject to a vulnerability due to improper input validation and output escaping. This issue allows authenticated users with Subscriber-level access and higher to embed malicious scripts through the User's Display Name. Once the script is injected, it will execute whenever other users visit the affected pages, potentially compromising their session data and web security.
Affected Version(s)
ForumWP β Forum & Discussion Board 0 <= 2.1.6