CVE-2026-28558 Details
Description
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user who views the attacker's profile page.
A stored cross-site scripting vulnerability has been identified in wpForo Forum version 2.4.14. This vulnerability allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload feature. Attackers can upload a specially crafted SVG that includes CSS injection or JavaScript event handlers. These malicious scripts are executed in the browsers of users who view the attacker's profile page.
Users can update to wpForo Forum version 2.4.16, which blocks SVG file uploads in avatars and addresses the XSS vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wordpress.org/plugins/wpforo/ | [email protected] | Product |
| https://wordpress.org/plugins/wpforo/#developers | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/wpforo-forum-stored-xss-via-svg-avatar-file-upload | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gvectors wpforo forum | >= 2.4.0, < 2.4.16 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2026 | Initial Analysis | [email protected] |
| Feb 28, 2026 | New CVE Received | [email protected] |