CVE-2026-12696: wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12696?
CVE-2026-12696 has a medium severity rating of 5.4.
How do I fix CVE-2026-12696?
To fix CVE-2026-12696, upgrade the wpForo Forum plugin to version 3.1.2 or later.
What type of vulnerability is CVE-2026-12696?
CVE-2026-12696 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Who can exploit CVE-2026-12696?
Users with a subscriber-level account can exploit CVE-2026-12696 to inject malicious JavaScript.
What impact does CVE-2026-12696 have on users?
CVE-2026-12696 allows injected JavaScript to execute in the browsers of any visitors to the affected profile page.