wpForo Forum
cpe:2.3:a:gvectors:wpforo:*:*:*:*:wordpress:*:*, +1 more
- <= 2.4.14
A stored cross-site scripting vulnerability has been identified in wpForo Forum version 2.4.14. This vulnerability allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload feature. Attackers can upload a specially crafted SVG that includes CSS injection or JavaScript event handlers. These malicious scripts are executed in the browsers of users who view the attacker's profile page.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the profile.
Users can update to wpForo Forum version 2.4.16, which blocks SVG file uploads in avatars and addresses the XSS vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.