CVE-2024-10879 Overview
The ForumWP – Forum & Discussion Board plugin for WordPress contains a Reflected Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 2.1.2. The flaw stems from unsafe use of add_query_arg and remove_query_arg without proper URL escaping in the plugin's admin emails list table. Unauthenticated attackers can inject arbitrary JavaScript that executes in a victim's browser when the victim clicks a crafted link. The issue is tracked under [CWE-79] and impacts both the free and Pro editions of the plugin distributed by Ultimatemember.
Critical Impact
Attackers can execute arbitrary scripts in an authenticated user's session context, enabling session theft, admin action forgery, or redirection to attacker-controlled infrastructure.
Affected Products
- Ultimatemember ForumWP (Free) for WordPress — all versions ≤ 2.1.2
- Ultimatemember ForumWP (Pro) for WordPress — all versions ≤ 2.1.2
- WordPress installations using the ForumWP admin emails list table
Discovery Timeline
- 2024-12-06 - CVE-2024-10879 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-10879
Vulnerability Analysis
The vulnerability resides in the ForumWP admin emails list table implementation at includes/admin/class-emails-list-table.php. The plugin passes the current request URL into add_query_arg and remove_query_arg without escaping the returned value before rendering it back into the page. WordPress documentation explicitly warns that both functions return unsanitized user input from $_SERVER['REQUEST_URI'], requiring developers to wrap the output in esc_url() before echoing it. Because the plugin omits this escaping step, an attacker can append crafted query parameters that break out of the URL context and inject HTML or JavaScript.
Root Cause
The root cause is missing output encoding on reflected request data, a classic Cross-Site Scripting weakness classified as [CWE-79]. The affected lines — 156 and 178 of the emails list table class — construct pagination and action URLs from the current request without calling esc_url(). This allows attacker-controlled query string content to render as executable markup on the admin page.
Attack Vector
Exploitation requires user interaction. An unauthenticated attacker crafts a malicious URL targeting the ForumWP admin emails screen and delivers it via phishing, forum posts, or social engineering. When an authenticated WordPress administrator clicks the link, the injected script executes in the browser under the WordPress origin. The script can steal session cookies, submit authenticated requests to WordPress admin endpoints, create rogue administrator accounts, or pivot to plugin configuration changes. Full technical detail is available in the Wordfence Vulnerability Report and the WordPress Changeset Overview that resolves the issue.
Detection Methods for CVE-2024-10879
Indicators of Compromise
- Web server access logs containing requests to WordPress admin URLs with query strings that include <script>, javascript:, onerror=, or URL-encoded equivalents such as %3Cscript%3E.
- Referer headers pointing to external domains immediately preceding administrative actions on /wp-admin/ pages related to ForumWP.
- Unexpected creation of WordPress administrator accounts or modifications to ForumWP settings shortly after an admin session.
Detection Strategies
- Deploy Web Application Firewall (WAF) rules that inspect query parameters submitted to /wp-admin/ pages for reflected script payloads.
- Enforce a strict Content Security Policy (CSP) on the WordPress admin surface and alert on CSP violation reports.
- Correlate outbound traffic from administrator browsers with anomalous domains referenced in reflected parameters.
Monitoring Recommendations
- Enable verbose access logging on WordPress admin endpoints and centralize logs for retention and search.
- Monitor for changes to wp_users, wp_usermeta, and ForumWP options tables that occur outside standard change windows.
- Track plugin version inventory across WordPress estates to identify hosts still running ForumWP ≤ 2.1.2.
How to Mitigate CVE-2024-10879
Immediate Actions Required
- Upgrade ForumWP to a version above 2.1.2 that includes the fix from changeset 3205107.
- Instruct WordPress administrators to avoid clicking untrusted links while authenticated to the admin dashboard.
- Rotate WordPress administrator session cookies and reset credentials if suspicious admin activity is observed.
Patch Information
The vendor addressed the flaw by escaping the URL output from add_query_arg and remove_query_arg in includes/admin/class-emails-list-table.php. Review the fix in the WordPress Changeset Overview and the vulnerable code paths at line 156 and line 178. Update through the WordPress plugin manager or WP-CLI.
Workarounds
- Deactivate the ForumWP plugin until an update can be applied if patching is not immediately feasible.
- Restrict access to /wp-admin/ via IP allowlisting on the reverse proxy or hosting control panel.
- Deploy a WAF signature that blocks reflected <script> and javascript: payloads in query strings targeting WordPress admin URLs.
# Update ForumWP via WP-CLI
wp plugin update forumwp
# Verify installed version is above 2.1.2
wp plugin get forumwp --field=version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.