Stored Cross-Site Scripting in wpForo Forum Plugin for WordPress
CVE-2025-4406

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 July 2025

What is CVE-2025-4406?

The wpForo Forum plugin for WordPress allows authenticated users with Subscriber-level access or higher to exploit a stored cross-site scripting vulnerability. This flaw arises from inadequate input sanitization concerning SVG file uploads, permitting attackers to inject harmful web scripts. When users access affected SVG files, the injected scripts execute, potentially compromising user sessions and data. Users are advised to update to the latest version of wpForo and ensure proper security measures are in place to mitigate risks.

Affected Version(s)

wpForo Forum * <= 2.4.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhan Luo
.
CVE-2025-4406 : Stored Cross-Site Scripting in wpForo Forum Plugin for WordPress