CVE-2026-28561

wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent JavaScript via forum description fields echoed without output escaping across multiple theme template files. On multisite installations or with a compromised admin account, attackers set a forum description containing HTML event handlers that execute when any user views the forum listing.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*

History

05 Mar 2026, 15:42

Type Values Removed Values Added
References () https://wordpress.org/plugins/wpforo/ - () https://wordpress.org/plugins/wpforo/ - Product
References () https://wordpress.org/plugins/wpforo/#developers - () https://wordpress.org/plugins/wpforo/#developers - Release Notes
References () https://www.vulncheck.com/advisories/wpforo-forum-stored-xss-via-unescaped-forum-description-in-templates - () https://www.vulncheck.com/advisories/wpforo-forum-stored-xss-via-unescaped-forum-description-in-templates - Third Party Advisory
CPE cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*
First Time Gvectors
Gvectors wpforo Forum

02 Mar 2026, 20:30

Type Values Removed Values Added
Summary
  • (es) wpForo Forum 2.4.14 contiene una vulnerabilidad de cross-site scripting almacenado que permite a los administradores inyectar JavaScript persistente a través de campos de descripción del foro mostrados sin escape de salida en múltiples archivos de plantilla de tema. En instalaciones multisitio o con una cuenta de administrador comprometida, los atacantes establecen una descripción del foro que contiene controladores de eventos HTML que se ejecutan cuando cualquier usuario ve el listado del foro.

28 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-28 22:16

Updated : 2026-03-05 15:42


NVD link : CVE-2026-28561

Mitre link : CVE-2026-28561

CVE.ORG link : CVE-2026-28561


JSON object : View

Products Affected

gvectors

  • wpforo_forum
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')