Description
WordPress Plugin wpForo Forum is prone to an open redirect vulnerability because the application fails to properly verify user-supplied input. Exploiting this issue may allow attackers to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. WordPress Plugin wpForo Forum version 1.9.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.9.7 or latest
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5342)
SharePoint CVE-2023-36890 Vulnerability (CVE-2023-36890)
WordPress Plugin Restaurant Menu-Food Ordering System-Table Reservation Security Bypass (2.3.0)
XWikiplatform URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2025-32970)
WordPress Plugin Responsive Gallery Grid Cross-Site Scripting (2.3.8)