CVE-2026-12696: Unknown Wpforo Forum

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator.

Affected products

  • Unknown Wpforo Forum: before 3.1.2 (fixed in 3.1.2)

Published 2026-08-01. Last modified 2026-08-26.