Description
WordPress Plugin WP Forum Server is prone to an SQL injection vulnerability and a cross-site scripting vulnerability. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin WP Forum Server version 1.7.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.5 or latest
References
Related Vulnerabilities
WordPress Plugin Events Manager 'events-manager.php' SQL Injection (2.1)
Drupal Core 8.3.0 Security Bypass (8.3.0)
Mibew Messenger Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-0829)
Joomla! Core Arbitrary File Upload (2.5.0 - 3.8.7)
WordPress Plugin Smart Manager for WooCommerce & WPeC SQL Injection (3.9.6)