CVE-2023-2309: Gvectors Wpforo Forum

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.

Affected products

  • Gvectors Wpforo Forum: before 2.1.9 (fixed in 2.1.9)

Published 2023-07-24. Last modified 2026-06-17.