← back
CVE-2023-2309

wpForo Forum < 2.1.9 - Reflected Cross-Site Scripting

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 0.8%
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
nono source reports it
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.
Affected products
Unknown · wpForo Forum