CyberRota Analysis
AI-GeneratedThe wpForo Forum WordPress plugin prior to version 3.1.2 is vulnerable due to inadequate sanitization of user profile fields, enabling subscriber-level users to inject malicious JavaScript into HTML attributes on public profile pages. This flaw poses a risk of cross-site scripting (XSS) attacks, potentially impacting any visitor, including logged-in administrators, who views the compromised profile. WordPress site administrators and users of the wpForo plugin should prioritize updating to the latest version to mitigate this vulnerability.
Original NVD Description
The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator.