CVE-2026-28561 Details
Description
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent JavaScript via forum description fields echoed without output escaping across multiple theme template files. On multisite installations or with a compromised admin account, attackers set a forum description containing HTML event handlers that execute when any user views the forum listing.
A stored cross-site scripting vulnerability has been identified in wpForo Forum version 2.4.14. This vulnerability allows administrators to inject persistent JavaScript into forum description fields, which are then echoed without proper output escaping across various theme template files. In multisite installations or with a compromised admin account, the injected scripts can execute when users view the forum listing.
Users are advised to update to wpForo Forum version 2.4.16, which addresses this vulnerability by fixing the output escaping issue in forum descriptions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wordpress.org/plugins/wpforo/ | [email protected] | Product |
| https://wordpress.org/plugins/wpforo/#developers | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/wpforo-forum-stored-xss-via-unescaped-forum-description-in-templates | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gvectors wpforo forum | >= 2.4.0, < 2.4.16 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2026 | Initial Analysis | [email protected] |
| Feb 28, 2026 | New CVE Received | [email protected] |