Junglewise Threat Intelligence

CVE-2026-78293: WP w3all phpBB cross-site scripting vulnerability

CVE-2026-78293 · Severity: high · CVSS 7.1 · Published 2026-08-27

Executive brief

WP w3all phpBB is a WordPress plugin that integrates phpBB forum functionality into WordPress sites. An unauthenticated attacker can inject malicious scripts that execute in the browsers of site visitors, potentially stealing their data or hijacking their accounts. The vulnerability affects versions up to 3.0.6 and requires user interaction (such as clicking a malicious link) to be exploited.

Technical details

This is an unauthenticated Cross-Site Scripting (XSS) vulnerability in the WP w3all phpBB WordPress plugin versions 3.0.6 and earlier. The vulnerability allows attackers to inject malicious scripts that execute in visitor browsers, classified as an injection-type flaw. Although the vulnerability is unauthenticated, successful exploitation requires a privileged user or victim to interact with a crafted payload (such as clicking a malicious link or visiting a specially crafted page). Attackers can leverage this to steal session data, credentials, or hijack user accounts. The vulnerability was patched in version 3.0.7, which is the recommended mitigation.

Affected products

  • axew3.com WP w3all phpBB 3.0.6 and earlier

Timeline

  • 2026-08-25: disclosed: Vulnerability published by Patchstack
  • 2026-08-27: patched: Fixed in version 3.0.7

References

Related threats