WordPress Plugin WP Forum Server Cross-Site Scripting and SQL Injection Vulnerabilities - CVE-2012-6622
WordPress Plugin WP Forum Server is prone to an SQL injection vulnerability and a cross-site scripting vulnerability. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials compromise the application access or modify data or exploit latent vulnerabilities in the underlying database. WordPress Plugin WP Forum Server version 1.7.3 is vulnerable prior versions may also be affected.