CVE-2022-38144 – WordPress wpForo Forum plugin <= 2.0.5 - Cross-Site Request Forgery (CSRF) vulnerability
https://notcve.org/view.php?id=CVE-2022-38144
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress. Una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en el plugin wpForo Forum de gVectors Team versiones anteriores a 2.0.5 incluyéndola, en WordPress The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to execute that function, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/wpforo/wordpress-wpforo-forum-plugin-2-0-5-cross-site-request-forgery-csrf-vulnerability/_s_id=cve https://wordpress.org/plugins/wpforo/#developers • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-24406 – wpForo Forum < 1.9.7 - Open Redirect
https://notcve.org/view.php?id=CVE-2021-24406
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands) El plugin wpForo Forum de WordPress versiones anteriores a 1.9.7,[ no comprueba el parámetro redirect_to en el formulario de inicio de sesión del foro, conllevando a un problema de redirección abierta tras un inicio de sesión con éxito. Este problema podría permitir a un atacante inducir a un usuario a usar una URL de inicio de sesión que redirigiera a un sitio web bajo su control y que fuera una réplica del legítimo, pidiéndole que volviera a introducir sus credenciales (que luego estarían en manos del atacante) • https://wpscan.com/vulnerability/a9284931-555b-4c96-86a3-09e1040b0388 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2019-19112 – wpForo Forum <= 1.6.5 - Cross-Site Scripting via wpf-dw-td-value class
https://notcve.org/view.php?id=CVE-2019-19112
The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php. El plugin wpForo versión 1.6.5 para WordPress, permite un ataque de tipo XSS involucrando la clase wpf-dw-td-value del archivo dashboard.php • https://twitter.com/Sh0ckFR/status/1257298443527053313 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-19110 – wpForo Forum <= 1.6.5 - Cross-Site Scripting via s parameter
https://notcve.org/view.php?id=CVE-2019-19110
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter. El plugin wpForo versión 1.6.5 para WordPress, permite un ataque de tipo XSS por medio del parámetro s de wp-admin/admin.php?page=wpforo-expressions • https://twitter.com/Sh0ckFR/status/1257298443527053313 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-19109 – wpForo Forum <= 1.6.5 - Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2019-19109
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. El plugin wpForo versión 1.6.5 para WordPress, permite un ataque de tipo CSRF de wp-admin/admin.php?page=wpforo-usergroups • https://twitter.com/Sh0ckFR/status/1257298443527053313 • CWE-352: Cross-Site Request Forgery (CSRF) •