CVE-2022-38055: WordPress wpForo Forum plugin <= 2.0.9 - Auth. HTML Injection vulnerability
Published Jun 21, 2024
·Updated
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Content Spoofing.This issue affects wpForo Forum: from n/a through 2.0.9.
Affected Software
1 affected component
gVectors Wpforo Forum Wordpress<2.1.0
Remediation
Information
Update to 2.1.0 or a higher version.
Event History
Jun 21, 2024
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-38055?
CVE-2022-38055 has been categorized as a high severity vulnerability due to its potential for content spoofing.
2
What systems are affected by CVE-2022-38055?
CVE-2022-38055 affects wpForo Forum versions from n/a through 2.0.9.
3
How do I fix CVE-2022-38055?
To fix CVE-2022-38055, upgrade your wpForo Forum to version 2.1.0 or later.
4
What type of vulnerability is CVE-2022-38055?
CVE-2022-38055 is an Improper Neutralization of Script-Related HTML Tags in a Web Page vulnerability, commonly known as Cross-Site Scripting (XSS).
5
What impact does CVE-2022-38055 have on web applications?
CVE-2022-38055 can allow attackers to perform content spoofing, potentially misleading users or compromising user interactions.