Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

wpForo Forum allows attackers to inject malicious code into profiles

CVE-2026-28558
Summary

An attacker can upload a special image to a user's profile picture, which can then be used to inject malicious code into other users' browsers when they view the profile. This is a serious security risk because it allows an attacker to take control of a user's browser. To fix this, update to the latest version of wpForo Forum.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
gvectors wpforo_forum > 2.4.0 , <= 2.4.16 –
Original title
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attack...
Original description
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user who views the attacker's profile page.
nvd CVSS3.1 5.4
nvd CVSS4.0 5.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 28 Feb 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026