wpForo Forum, CVE-2018-11709
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jun 04, 2018
- Research Description
- wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.
- Affected versions
-
Min -, max 1.4.12.
- Status
-
vulnerable