WordPress wpForo Forum plugin before 1.4.12 for WordPress allows unauthenticated reflected cross-site scripting via the URI.
View the template here CVE-2018-11709.yaml
echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-11709.yaml
References: