Medium severity6.1NVD Advisory· Published Jun 4, 2018· Updated Jun 17, 2026
CVE-2018-11709
CVE-2018-11709
Description
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<1.4.12+ 1 more
- (no CPE)range: <1.4.12
- (no CPE)range: <1.4.12
Package: https://wordpress.org/plugins/wpforo
Patches
Vulnerability mechanics
References
3- blog.dewhurstsecurity.com/2018/06/01/wp-foro-wordpress-plugin-xss-vulnerability.htmlnvdThird Party Advisory
- wpvulndb.com/vulnerabilities/9090nvdThird Party Advisory
- wordpress.org/plugins/wpforo/nvdRelease Notes
News mentions
0No linked articles in our index yet.