The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 24 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-24T15:02:54.084Z
Reserved: 2023-04-26T18:21:16.754Z
Link: CVE-2023-2309
Updated: 2024-08-02T06:19:14.681Z
Status : Modified
Published: 2023-07-24T11:15:09.653
Modified: 2024-11-21T07:58:21.430
Link: CVE-2023-2309
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.