What is CVE-2026-12696?
The wpForo Forum WordPress plugin versions before 3.1.2 lack sanitization and escaping on a user profile field, outputting it inside an HTML attribute on public participant profile pages. This allows users with a subscriber-level account to inject JavaScript, leading to a Stored XSS vulnerability that executes in the browser of any visitor viewing the profile. Affected sites should update the plugin to version 3.1.2 or later immediately.
Azərbaycanca: wpForo Forum WordPress plaginində 3.1.2 versiyasından əvvəlki versiyalarda, istifadəçi profili sahəsi sanitizasiya edilmir, bu da sadə abunəçi səviyyəli istifadəçilərə ictimai profil səhifəsində JavaScript kodu yeritməyə imkan verir. Bu, həmin səhifəyə daxil olan istənilən ziyarətçinin brauzerində kodun icrası ilə nəticələnə bilən Stored XSS zəifliyidir. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
From which version of the wpForo Forum plugin is the CVE-2026-12696 vulnerability fixed?
The stored XSS vulnerability is resolved by updating the plugin to version 3.1.2 or later.
What level of user can inject JavaScript code using the CVE-2026-12696 vulnerability?
Users with subscriber-level accounts can inject JavaScript code via their profile field through this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.