cleantalk
Vulnerabilities and Security Researches

wpForo Forum, CVE-2018-11709

CVE, Research URL

CVE-2018-11709

Application

wpForo Forum

Published on
Jun 04, 2018
Research Description
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.
Affected versions
Min -, max 1.4.12.
Status
vulnerable