PT-2026-98395 · WordPress · Wpforo Forum
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
wpForo Forum versions prior to 3.1.7
Description
Stored Cross-Site Scripting occurs via the 'telegram' profile field due to insufficient input sanitization and output escaping in the
profile update action. The raw $ POST['data'] array is copied into a $custom fields variable before the validate() and sanitize() functions are executed; since these functions only operate on a parallel $user reference, $custom fields remains unsanitized when saved via update custom fields(). During rendering, wpforo decode() reverses entity encoding, and the value is echoed without escaping in field wrap profile(). This allows authenticated attackers with subscriber-level access or higher to inject arbitrary web scripts that execute when a user visits the affected page.Recommendations
Update to a version newer than 3.1.6.
As a temporary mitigation, restrict the use of the 'telegram' profile field until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpforo Forum