๐Ÿ” CVE Alert

CVE-2026-28560

MEDIUM 5.5

wpForo Forum 2.4.14 Stored XSS via Unsafe JSON Encoding in Inline Script

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows script injection via forum URL data output into an inline script block using json_encode without the JSON_HEX_TAG flag. Attackers set a forum slug containing a closing script tag or unescaped single quote to break out of the JavaScript string context and execute arbitrary script in all visitors' browsers.

CWE CWE-79
Vendor gvectors team
Product wpforo forum
Published Feb 28, 2026
Last Updated Mar 6, 2026
Stay Ahead of the Next One

Get instant alerts for gvectors team wpforo forum

Be the first to know when new medium vulnerabilities affecting gvectors team wpforo forum are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

gVectors Team / wpForo Forum
2.4 < 2.4.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordpress.org: https://wordpress.org/plugins/wpforo/ wordpress.org: https://wordpress.org/plugins/wpforo/#developers vulncheck.com: https://www.vulncheck.com/advisories/wpforo-forum-stored-xss-via-unsafe-json-encoding-in-inline-script

Credits

Scott Moore - VulnCheck