Description
WordPress Plugin WP Forum Server is prone to an SQL injection vulnerability and a cross-site scripting vulnerability. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin WP Forum Server version 1.7.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.5 or latest
References
Related Vulnerabilities
WordPress Plugin JetWidgets for Elementor and WooCommerce Local File Inclusion (1.1.7)
WordPress Plugin Newsletter-Send awesome emails from WordPress Multiple Vulnerabilities (6.8.1)
WordPress 6.2.x Cross-Site Scripting (6.2 - 6.2.4)
WordPress Plugin Child Theme Creator by Orbisius Cross-Site Request Forgery (1.5.1)