Impact
Subscriber Cross Site Scripting (XSS) exists in WordPress wpForo Forum plugin version 3.1.5 and earlier. The flaw allows an attacker to inject malicious JavaScript that executes within the browser session of any user who views the affected content, which can lead to session hijacking, credential theft, defacement, or other client‑side attacks. The weakness is a classic reflected or stored input validation issue (CWE‑79).
Affected Systems
The vulnerability affects the Tomdever "wpForo Forum" plugin for WordPress. All installations running version 3.1.5 or older are susceptible. The vendor recommends upgrading to version 3.1.6 or later to contain the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. An attacker can exploit the flaw via the web interface, typically by creating or editing forum posts that contain malicious script. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is Web, and the threat requires a user to view the compromised content to realize the impact. Overall risk is moderate to high for sites with active forums and unauthenticated users.
OpenCVE Enrichment