← Volver a CVEs
CVE-2026-28558
MEDIUM6.4
Descripcion
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user who views the attacker's profile page.
Detalles CVE
Puntuacion CVSS v3.16.4
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado2/28/2026
Ultima modificacion3/4/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
gvectors:wpforo_forum
Debilidades (CWE)
CWE-79
Referencias
https://wordpress.org/plugins/wpforo/(disclosure@vulncheck.com)
https://wordpress.org/plugins/wpforo/#developers(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/wpforo-forum-stored-xss-via-svg-avatar-file-upload(disclosure@vulncheck.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.