Impact
wpForo Forum version 2.4.14 contains a stored cross‑site scripting vulnerability that can be triggered by uploading a malicious SVG file as a user avatar. The uploaded SVG may contain CSS or JavaScript that runs in the browser whenever any site visitor loads the avatar image. This leads to client‑side code execution with the privileges of the viewing user.
Affected Systems
The flaw exists in the GVectors Team wpForo Forum plugin, specifically in version 2.4.14. Versions 2.4.16 and later contain a fix, as indicated by the product data.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the KEV catalog. Exploitation requires an authenticated subscriber to upload a crafted SVG; any user who views the attacker’s profile will execute the injected code.
OpenCVE Enrichment