CVE-2018-11709
Description
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated reflected XSS in wpForo Forum plugin before 1.4.12 for WordPress via the wpforo_get_request_uri function.
Vulnerability
The wpForo Forum plugin for WordPress versions before 1.4.12 contain a reflected cross-site scripting (XSS) vulnerability in the wpforo_get_request_uri function located in wpf-includes/functions.php. The function does not properly sanitize the HTTP request URI before outputting it, allowing an attacker to inject arbitrary JavaScript code. The vulnerability is reachable without authentication, as the function can be triggered by any visitor to the site.
Exploitation
An unauthenticated attacker can craft a malicious URI containing JavaScript payload and trick a victim into clicking a link to the crafted URL. No special network position, user interaction beyond clicking the link, or prior authentication is required. The injected script will execute in the context of the vulnerable WordPress site.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser session on the WordPress site. This can lead to session hijacking, defacement, or theft of sensitive information such as cookies and form data. The attack is reflected, meaning the payload is only present in the crafted link and does not persist on the server.
Mitigation
The vulnerability is fixed in wpForo Forum plugin version 1.4.12 [1]. Users should update to version 1.4.12 or later immediately. No workarounds are documented; upgrading the plugin is the recommended mitigation.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <1.4.12
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- blog.dewhurstsecurity.com/2018/06/01/wp-foro-wordpress-plugin-xss-vulnerability.htmlmitrex_refsource_MISC
- wordpress.org/plugins/wpforo/mitrex_refsource_MISC
- wpvulndb.com/vulnerabilities/9090mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.