SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-12696

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The wpForo Forum WordPress plugin prior to version 3.1.2 is vulnerable due to inadequate sanitization of user profile fields, enabling subscriber-level users to inject malicious JavaScript into HTML attributes on public profile pages. This flaw poses a risk of cross-site scripting (XSS) attacks, potentially impacting any visitor, including logged-in administrators, who views the compromised profile. WordPress site administrators and users of the wpForo plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-12696
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%
WordPress Java

Original NVD Description

The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator.