CVE-2018-11709: XSS
Published Jun 4, 2018
·Updated
wpforogetrequesturi in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.
Affected Software
1 affected component
gVectors Wpforo Forum Wordpress<1.4.12
Event History
Jun 4, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the wpForo Forum plugin?
The vulnerability ID for the wpForo Forum plugin is CVE-2018-11709.
2
What is the severity rating of CVE-2018-11709?
The severity rating of CVE-2018-11709 is medium with a CVSS score of 6.1.
3
How does CVE-2018-11709 affect the wpForo Forum plugin?
CVE-2018-11709 allows Unauthenticated Reflected Cross-Site Scripting (XSS) through the URI in the wpForo Forum plugin before version 1.4.12 for WordPress.
4
What is the affected software of CVE-2018-11709?
The affected software of CVE-2018-11709 is the wpForo Forum plugin before version 1.4.12 for WordPress.
5
How can I fix the CVE-2018-11709 vulnerability in wpForo Forum?
To fix the CVE-2018-11709 vulnerability in wpForo Forum, you should update the plugin to version 1.4.12 or later.