Stored Cross-Site Scripting in wpForo Forum Plugin for WordPress
CVE-2025-4406
5.4MEDIUM
What is CVE-2025-4406?
The wpForo Forum plugin for WordPress allows authenticated users with Subscriber-level access or higher to exploit a stored cross-site scripting vulnerability. This flaw arises from inadequate input sanitization concerning SVG file uploads, permitting attackers to inject harmful web scripts. When users access affected SVG files, the injected scripts execute, potentially compromising user sessions and data. Users are advised to update to the latest version of wpForo and ensure proper security measures are in place to mitigate risks.
Affected Version(s)
wpForo Forum * <= 2.4.5