The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Wpforo_forum | Gvectors | * | 2.1.9 (excluding) |
References