CVE-2019-19110: XSS
Published Jun 15, 2020
·Updated
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
Affected Software
1 affected component
gVectors Wpforo Wordpress=1.6.5
Event History
Jun 15, 2020
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
Description
Frequently Asked Questions
1
What is CVE-2019-19110?
CVE-2019-19110 is a vulnerability found in the wpForo plugin 1.6.5 for WordPress that allows XSS (Cross-Site Scripting) attacks.
2
How can the wpForo plugin 1.6.5 be exploited?
The wpForo plugin 1.6.5 can be exploited by sending a specially crafted request to the wp-admin/admin.php?page=wpforo-phrases s parameter.
3
What is the severity of CVE-2019-19110?
CVE-2019-19110 has a severity level of medium with a score of 4.8.
4
How can I fix the wpForo plugin 1.6.5?
To fix the wpForo plugin 1.6.5, you should update it to the latest version available.
5
Where can I find more information about CVE-2019-19110?
You can find more information about CVE-2019-19110 on the official CVE website or through the provided reference link: https://twitter.com/Sh0ckFR/status/1257298443527053313