Impact
The wpForo Forum WordPress plugin before version 3.1.2 does not sanitize the profile Location field before outputting it inside an HTML attribute on the public participant profile page. Subscribers can insert malicious JavaScript that runs in the browsers of any visitor who views the profile, including logged‑in administrators. This stored XSS allows attackers to execute arbitrary client‑side code when the page is rendered.
Affected Systems
WordPress sites running the wpForo Forum plugin before version 3.1.2 are affected.
Risk and Exploitability
Although the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, the presence of a stored XSS can be abused if a subscriber creates a malicious profile and a user—including a privileged user—views the profile. The exploitation requires only a subscriber account and exposure of the public profile page. The CVSS score is 5.4.
OpenCVE Enrichment