CVE-2019-19112: XSS
Published Jun 15, 2020
·Updated
The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.
Affected Software
1 affected component
gVectors Wpforo Wordpress=1.6.5
Event History
Jun 15, 2020
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this wpForo plugin vulnerability?
The vulnerability ID for this wpForo plugin vulnerability is CVE-2019-19112.
2
What is the affected version of the wpForo plugin?
The affected version of the wpForo plugin is 1.6.5.
3
What is the severity of CVE-2019-19112?
The severity of CVE-2019-19112 is medium with a CVSS score of 6.1.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79 (Cross-Site Scripting).
5
Is there a fix available for this vulnerability?
Yes, the vendor has released a fix for this vulnerability. It is recommended to update to the latest version of the wpForo plugin.