CVE-2023-47872: WordPress wpForo Forum Plugin <= 2.2.3 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.This issue affects wpForo Forum: from n/a through 2.2.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-47872?
CVE-2023-47872 is a vulnerability in the WordPress wpForo Forum Plugin, allowing for Cross Site Scripting (XSS) attacks.
How severe is CVE-2023-47872?
CVE-2023-47872 has a severity score of 6.5 out of 10, indicating a medium-level threat.
How does CVE-2023-47872 affect wpForo Forum?
CVE-2023-47872 affects wpForo Forum versions up to and including 2.2.3.
What is Cross Site Scripting (XSS)?
Cross Site Scripting (XSS) is a type of vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
How can I fix CVE-2023-47872 in wpForo Forum Plugin?
To fix the CVE-2023-47872 vulnerability in wpForo Forum Plugin, you should update to a version later than 2.2.3, as the issue has been addressed and patched.