WordPress Plugin Vulnerabilities

wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field

Description

The plugin does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator.

Proof of Concept

Affects Plugins

Fixed in 3.1.2

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes

Timeline

Publicly Published
2026-07-20 (about 1 month ago)
Added
2026-07-20 (about 1 month ago)
Last Updated
2026-08-21 (about 1 day ago)

Other