PatchSiren

wpForo Forum CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review wpForo Forum CVE published 2026-08-01

CVE-2026-12696

The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator. This vulnerability is categorized as a JavaScript inj [truncated]