CVE-2025-4224: wpForo + wpForo Advanced Attachments <= 3.1.3 - Unauthenticated Stored Cross-Site Scripting
The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4224?
CVE-2025-4224 has been rated as a medium severity vulnerability due to the potential for storing malicious scripts.
How do I fix CVE-2025-4224?
To fix CVE-2025-4224, update the wpForo + wpForo Advanced Attachments plugin to version 3.1.4 or later.
Who is affected by CVE-2025-4224?
CVE-2025-4224 affects users of the wpForo + wpForo Advanced Attachments plugin on WordPress versions up to and including 3.1.3.
What type of vulnerability is CVE-2025-4224?
CVE-2025-4224 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2025-4224 be exploited by unauthenticated users?
No, exploiting CVE-2025-4224 requires authentication, which means only logged-in users can conduct the attack.