CVE-2026-28558

MEDIUM

wpForo Forum 2.4.0-2.4.15 - Authenticated Stored Cross-Site Scripting via SVG Avatar Upload

Title source: llm
STIX 2.1

Description

wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user who views the attacker's profile page.

Scores

CVSS v3 6.4
EPSS 0.0021
EPSS Percentile 10.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
gvectors/wpforo_forum 2.4.0 - 2.4.16
gVectors Team/wpForo Forum 2.4 - 2.4.16
gVectors Team/wpForo Forum 2.4.16
Published Feb 28, 2026
Tracked Since Mar 01, 2026