<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									WP Engine Plugin Vulnerability notice? - Bug Reports - wpForo 2.0				            </title>
            <link>https://wpforo.com/community/general-forums-bug-reports/wp-engine-plugin-vulnerability-notice/</link>
            <description>Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Sun, 19 Jul 2026 15:18:59 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>RE: WP Engine Plugin Vulnerability notice?</title>
                        <link>https://wpforo.com/community/general-forums-bug-reports/wp-engine-plugin-vulnerability-notice/#post-106699</link>
                        <pubDate>Thu, 30 Nov 2023 11:43:44 +0000</pubDate>
                        <description><![CDATA[Fantastic - thank you! I think they must have scanned before 2.2.6  
Updated my sites now.
Thanks again.]]></description>
                        <content:encoded><![CDATA[<p>Fantastic - thank you! I think they must have scanned before 2.2.6  </p>
<p>Updated my sites now.</p>
<p>Thanks again.</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-forums-bug-reports/">Bug Reports - wpForo 2.0</category>                        <dc:creator>FaithT</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-forums-bug-reports/wp-engine-plugin-vulnerability-notice/#post-106699</guid>
                    </item>
				                    <item>
                        <title>RE: WP Engine Plugin Vulnerability notice?</title>
                        <link>https://wpforo.com/community/general-forums-bug-reports/wp-engine-plugin-vulnerability-notice/#post-106698</link>
                        <pubDate>Thu, 30 Nov 2023 11:29:45 +0000</pubDate>
                        <description><![CDATA[Hi @faitht
Sorry, but all the vulnerabilities have been fixed in previous versions of wpForo. The latest version is 2.2.6, and all reported vulnerabilities have now been addressed.
Perhaps...]]></description>
                        <content:encoded><![CDATA[<p><span>Hi @faitht</span></p>
<p><span>Sorry, but all the vulnerabilities have been fixed in previous versions of wpForo. The latest version is 2.2.6, and all reported vulnerabilities have now been addressed.</span></p>
<p>Perhaps wpscan or wordfence has not yet synchronized all the data in their databases.</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-forums-bug-reports/">Bug Reports - wpForo 2.0</category>                        <dc:creator>BlackRaz</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-forums-bug-reports/wp-engine-plugin-vulnerability-notice/#post-106698</guid>
                    </item>
				                    <item>
                        <title>WP Engine Plugin Vulnerability notice?</title>
                        <link>https://wpforo.com/community/general-forums-bug-reports/wp-engine-plugin-vulnerability-notice/#post-106694</link>
                        <pubDate>Thu, 30 Nov 2023 10:25:21 +0000</pubDate>
                        <description><![CDATA[We have two sites running WP Foro, both hosted with WP Engine.
We had this Vulnerability notice today and are not sure what to do, can you help please?
 
At WP Engine we take the security...]]></description>
                        <content:encoded><![CDATA[<p>We have two sites running WP Foro, both hosted with WP Engine.</p>
<p>We had this Vulnerability notice today and are not sure what to do, can you help please?</p>
<p> </p>
<p>At WP Engine we take the security of your sites very seriously, and make every effort to keep our customers aware of any potential security risks. We are reaching out to you today because we identified resources that may be utilizing a vulnerable version of the <strong>wpforo plugin. </strong></p>
<p>WP Engine summary of the vulnerability: The software does not perform an authorization check when an actor attempts to access a resource or perform an action. Finally, data from an attacker could be interpreted as code by site visitors’ web browsers. The ability to run code in another site visitors’ browser can be abused to steal information, or modify site configuration.</p>
<p>This vulnerability’s information has not been verified by WPScan. Please note that questions related to this notification should be directed to WPScan, the plugin Author or the 3rd-party researcher for the most accurate information.</p>
<p>Resources providing further information on this vulnerability:</p>
<p>https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47869 <br />https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47872 <br />https://wpscan.com/vulnerability/05cbb6f0-d01e-4192-84a7-19ddbd72613f https://wpscan.com/vulnerability/2171845d-8d3b-4e51-9e69-8d3a5447192d https://www.wordfence.com/threat-intel/vulnerabilities/id/5607a60e-a04a-4d28-bb04-bdacf8e97c56 https://www.wordfence.com/threat-intel/vulnerabilities/id/71078aaf-9803-4b46-bc94-dbcb43745629</p>
<p>There does not appear to be a fix for this update at this moment and we recommend updating when one becomes available.</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-forums-bug-reports/">Bug Reports - wpForo 2.0</category>                        <dc:creator>FaithT</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-forums-bug-reports/wp-engine-plugin-vulnerability-notice/#post-106694</guid>
                    </item>
							        </channel>
        </rss>
		