Record summary

CVE-2018-11709 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2018-11709Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 879 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress wpForo Forum <= 1.4.11 - Cross-Site ScriptingCVSS 6.1

WordPress wpForo Forum plugin before 1.4.12 for WordPress allows unauthenticated reflected cross-site scripting via the URI.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected website, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Update to the latest version of the wpForo Forum plugin (1.4.11) or apply the vendor-provided patch to fix the vulnerability.

WeaknessesCWE-79
Authorsdaffainfo, s4e-io
Template tagscvecve2018wordpressxsswp-plugingvectorsvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4