WordPress WP Forum Server Stored Cross-Site Scripting Vulnerability via Cross-Site Request Forgery
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress WP Forum Server plugin, affecting versions through 1.8.2, allows for Stored Cross-Site Scripting (XSS) attacks. This vulnerability could enable an attacker to manipulate users with higher privileges into performing actions that could lead to the execution of malicious scripts.
Impact
Exploitation of this vulnerability could result in Stored Cross-Site Scripting, where injected scripts are executed in the context of the user.
Remediation
No official fix is available for this vulnerability. Users are advised to remove and replace the WP Forum Server plugin, as it is likely abandoned and will not receive further updates or fixes.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
