CVE-2023-2309: wpForo Forum < 2.1.9 - Reflected Cross-Site Scripting
Published Jul 24, 2023
·Updated
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.
Affected Software
1 affected component
gVectors Wpforo Forum Wordpress<2.1.9
Event History
Jul 24, 2023
CVE Published
via MITRE·10:20 AM
Data Sourced
via MITRE·10:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this wpForo Forum WordPress plugin vulnerability?
The vulnerability ID for this wpForo Forum WordPress plugin vulnerability is CVE-2023-2309.
2
What is the severity of CVE-2023-2309?
The severity of CVE-2023-2309 is medium with a severity value of 6.1.
3
What is the affected software for CVE-2023-2309?
The affected software for CVE-2023-2309 is the wpForo Forum WordPress plugin version up to 2.1.9.
4
What is the nature of the vulnerability in CVE-2023-2309?
The vulnerability in CVE-2023-2309 is a Reflected Cross-Site Scripting vulnerability.
5
Is there any fix available for CVE-2023-2309?
Yes, the fix for CVE-2023-2309 is to update the wpForo Forum WordPress plugin to version 2.1.9 or higher.