PT-2026-98395 · WordPress · Wpforo Forum

·

CVE-2026-93747

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions wpForo Forum versions prior to 3.1.7
Description Stored Cross-Site Scripting occurs via the 'telegram' profile field due to insufficient input sanitization and output escaping in the profile update action. The raw $ POST['data'] array is copied into a $custom fields variable before the validate() and sanitize() functions are executed; since these functions only operate on a parallel $user reference, $custom fields remains unsanitized when saved via update custom fields(). During rendering, wpforo decode() reverses entity encoding, and the value is echoed without escaping in field wrap profile(). This allows authenticated attackers with subscriber-level access or higher to inject arbitrary web scripts that execute when a user visits the affected page.
Recommendations Update to a version newer than 3.1.6. As a temporary mitigation, restrict the use of the 'telegram' profile field until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93747

Affected Products

Wpforo Forum