Executive brief
The wpForo Forum plugin for WordPress, which adds community discussion features to websites, contains a security flaw in how it handles user profile information. An attacker with a basic member account can save malicious code into their profile that will run in the browser of anyone who views their page, including site administrators. This could allow the attacker to hijack administrator sessions or perform unauthorized actions on the website.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the wpForo Forum plugin for WordPress prior to version 3.1.2. The issue stems from a failure to properly sanitize and escape user profile fields (specifically the location field) before rendering them within HTML attributes on public participant profile pages. An attacker with at least 'Subscriber' level privileges can inject malicious JavaScript into their profile. When a victim, such as a site administrator, views the affected profile, the script executes in their browser session. This can lead to session hijacking, unauthorized administrative actions, or further site compromise. The vulnerability is fixed in version 3.1.2.
Affected products
- gVectors Team wpForo Forum < 3.1.2
Timeline
- 2026-07-20: disclosed
- 2026-07-20: advisory: WPScan advisory published
- 2026-08-01: patched: NVD publication date; fix available in 3.1.2