plugin

Wpforo Advanced Attachments Vulnerabilities

1 known security issue reported for the Wpforo Advanced Attachments WordPress plugin. Most recent disclosed Jun 2, 2025.

1 high

Running Wpforo Advanced Attachments on your site? Check whether your installed version is affected.

Scan your site free

wpForo + wpForo Advanced Attachments <= 3.1.3 - Unauthenticated Stored Cross-Site Scripting

high

The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above...

CVSS:
7.2
Affected:
up to 3.1.3
Fixed in:
3.2.0
Disclosed:
Jun 2, 2025

CVE-2025-4224 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database