Loading
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.
Use Gvectors vendor hub and Wpforo Forum product page to widen CVE-2023-2309 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-28562, CVE-2024-43289 and CVE-2026-28557 for nearby disclosures in the same product family.