VYPR
Unrated severityNVD Advisory· Published Feb 28, 2026· Updated Mar 6, 2026

wpForo Forum 2.4.14 Stored XSS via Unsafe JSON Encoding in Inline Script

CVE-2026-28560

Description

wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows script injection via forum URL data output into an inline script block using json_encode without the JSON_HEX_TAG flag. Attackers set a forum slug containing a closing script tag or unescaped single quote to break out of the JavaScript string context and execute arbitrary script in all visitors' browsers.

Affected products

2
  • Minibb/Forumllm-fuzzy
    Range: =2.4.14
  • gVectors Team/wpForo Forumv5
    Range: 2.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.