<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									#WordPress wpForo plugin - Bug Reports - wpForo 2.0				            </title>
            <link>https://wpforo.com/community/general-forums-bug-reports/wordpress-wpforo-plugin/</link>
            <description>Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Sat, 05 Sep 2026 17:57:28 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>RE: #WordPress wpForo plugin</title>
                        <link>https://wpforo.com/community/general-forums-bug-reports/wordpress-wpforo-plugin/#post-106654</link>
                        <pubDate>Wed, 29 Nov 2023 14:05:14 +0000</pubDate>
                        <description><![CDATA[@blackraz IF we all use really some GOOD firewall (in PREPEND/ADVANCED mode), even IF issues exists, they are blocked. In ALL plugins, not just wpForo.
Use Ninja Firewall, and sleep at nigh...]]></description>
                        <content:encoded><![CDATA[<p>@blackraz IF we all use really some GOOD firewall (in PREPEND/ADVANCED mode), even IF issues exists, they are blocked. In ALL plugins, not just wpForo.</p>
<p>Use Ninja Firewall, and sleep at night.</p>
<p>https://wordpress.org/plugins/ninjafirewall/</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-forums-bug-reports/">Bug Reports - wpForo 2.0</category>                        <dc:creator>dimalifragis</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-forums-bug-reports/wordpress-wpforo-plugin/#post-106654</guid>
                    </item>
				                    <item>
                        <title>RE: #WordPress wpForo plugin</title>
                        <link>https://wpforo.com/community/general-forums-bug-reports/wordpress-wpforo-plugin/#post-106652</link>
                        <pubDate>Wed, 29 Nov 2023 13:38:55 +0000</pubDate>
                        <description><![CDATA[@chris-vaz
@realact
No real major issues were found. We have specifically released wpForo version 2.2.6, and we hope that the individuals who reported the vulnerabilities will confirm on t...]]></description>
                        <content:encoded><![CDATA[<p><span>@chris-vaz</span></p>
<p><span>@realact</span></p>
<p><span>No real major issues were found. We have specifically released wpForo version 2.2.6, and we hope that the individuals who reported the vulnerabilities will confirm on their end that the status has been fixed.</span></p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-forums-bug-reports/">Bug Reports - wpForo 2.0</category>                        <dc:creator>BlackRaz</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-forums-bug-reports/wordpress-wpforo-plugin/#post-106652</guid>
                    </item>
				                    <item>
                        <title>RE: #WordPress wpForo plugin</title>
                        <link>https://wpforo.com/community/general-forums-bug-reports/wordpress-wpforo-plugin/#post-106628</link>
                        <pubDate>Wed, 29 Nov 2023 01:55:08 +0000</pubDate>
                        <description><![CDATA[Well, according to the change log for version 2.2.5, this vulnerability was fixed.  So either the fix was ineffective, and they have discovered that it can still be exploited even after the ...]]></description>
                        <content:encoded><![CDATA[<p>Well, according to the change log for version <span>2.2.5, this vulnerability was fixed.  So either the fix was ineffective, and they have discovered that it can still be exploited even after the fix, or they have not reviewed the new version enough to notice it was fixed.</span></p>
<p>So yeah, we must wait for the Developers to respond. Furthermore, I don't believe this is a severe vulnerability, as all they can do is log out a user from the site IF they get that user to click on a specifically crafted link. Correct me if I'm wrong, but I think that's all there is to it.</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-forums-bug-reports/">Bug Reports - wpForo 2.0</category>                        <dc:creator>RealAct</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-forums-bug-reports/wordpress-wpforo-plugin/#post-106628</guid>
                    </item>
				                    <item>
                        <title>#WordPress wpForo plugin</title>
                        <link>https://wpforo.com/community/general-forums-bug-reports/wordpress-wpforo-plugin/#post-106627</link>
                        <pubDate>Tue, 28 Nov 2023 22:36:25 +0000</pubDate>
                        <description><![CDATA[Hi,My security plugin tells me this#WordPress wpForo plugin &lt;= 2.2.5 - Cross Site Request Forgery (CSRF) on Sign-out vulnerability-Vulnerability type: Cross Site Request Forgery (CSRF)-No...]]></description>
                        <content:encoded><![CDATA[<p>Hi,<br /><br />My security plugin tells me this<br /><br /><span>#WordPress wpForo plugin &lt;= 2.2.5 - Cross Site Request Forgery (CSRF) on Sign-out vulnerability</span><br /><span>-Vulnerability type: Cross Site Request Forgery (CSRF)</span><br /><span>-No Update Available</span><br /><br />I see in the previous updates it says it fixes it, but looks like its persistent.<br /><br />What can we the users of the plugin do to avoid attacks?<br /><br />Same with XXS?</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-forums-bug-reports/">Bug Reports - wpForo 2.0</category>                        <dc:creator>chris.vaz</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-forums-bug-reports/wordpress-wpforo-plugin/#post-106627</guid>
                    </item>
							        </channel>
        </rss>
		