CVE-2026-93772: WordPress wpForo Forum plugin <= 3.1.5 - Cross Site Scripting (XSS) vulnerability
Published Sep 23, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.
Affected Software
1 affected component
gVectors wpForo Forum<=3.1.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress wpForo Forum Pluginto a version that resolves this vulnerability.Fixed in 3.1.6
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated user with Subscriber-level access can exploit the XSS vulnerability. Exploitation also requires user interaction, as indicated by the UI:R vector.
2
What versions are affected?
wpForo Forum versions up to and including 3.1.5 are affected.
3
What impact can successful exploitation have?
The vulnerability can affect confidentiality, integrity, and availability at a low level, and its scope can extend beyond the vulnerable component.