CVE-2026-78293: WordPress WP w3all phpBB plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP w3all phpBB Pluginto a version that resolves this vulnerability.Fixed in 3.0.7
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress or phpBB account. Exploitation still requires user interaction, as reflected by the UI:R vector.
Which installations are affected?
WP w3all phpBB plugin versions 3.0.6 and earlier are identified as affected. The provided information does not state whether any particular plugin configuration or WordPress setup is required.
What impact can successful exploitation have?
Successful XSS can affect confidentiality, integrity, and availability at a low impact level, and the scope may extend beyond the vulnerable component. The supplied data does not specify the exact payload delivery method or actions available to an attacker.