cleantalk
Vulnerabilities and Security Researches

wpForo Forum, CVE-2026-28558

CVE, Research URL

CVE-2026-28558

Application

wpForo Forum

Published on
Mar 01, 2026
Research Description
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user who views the attacker's profile page.
Affected versions
max 2.4.14.
Status
vulnerable