CVE-2026-1581Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 1 mentions (2026-02-19); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-03-20: 1Mentions · 2026-10-02: 1Mentions · 2026-10-04: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 1Technical Details · 2026-03-20: 102-1902-2003-2010-0210-04
Signal classification1 categories
Disclosure
3100.0%
Referenced assets5 URLs
Full discourse5 posts
  • Ricardo Albuquerque@ralbuque

    SQL injection sem autenticação no plugin wpForo Forum (WordPress) está sendo explorada: CVE-2026-1581, CVSS 7.5, versões até 2.4.14. Atualize o plugin. E o backdoor "SC" se recria a partir de arquivos, banco e memória: limpar só os arquivos não basta. https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html

    1101211.1K
    20.1K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1581 - critical 🚨 wpForo Forum <= 2.4.14 - SQL Injection > wpForo Forum WordPress plugin <= 2.4.14 contains a time-based SQL injection caused by... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1581 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a critical time‑based SQL injection vulnerability (CVE‑2026‑1581) affecting wpForo Forum WordPress plugin versions up to 2.4.14 and provides a link to a library entry with additional information.

    0002088
    900 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews

    WordPress SC backdoor uses files, database, and shared memory to rebuild itself after cleanup, hide admin access, and persist via a hidden account. Active abuse targets wpForo flaw CVE-2026-1581. #WordPress #wpForo #CVE20261581 https://www.hendryadrian.com/wordpress-backdoor-rebuilds-itself-after-cleanup-using-files-database-and-shared-memory/

    00000233
    4.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1581 SQL Injection Vulnerability in wpForo Forum Plugin for WordPress Versions 2.4.14 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1581

    Post summary

    CVE-2026-1581 is a SQL injection flaw in the wpForo Forum Plugin for WordPress versions 2.4.14 and earlier; no PoC, exploit, or patch details are provided in the text.

    0000049
    4.0K followersView on X
  • Volerion@VolerionSec
    Disclosure

    🚨 CVE-2026-1581: wpForo Forum plugin lets unauthenticated users run time-based SQL injection and read your WordPress data. Update to 2.4.15+ now! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-1581 #WordPress #infosec #AppSec

    Post summary

    CVE-2026-1581 enables unauthenticated attackers to perform time‑based SQL injection in wpForo, exposing WordPress data; users should update to version 2.4.15 or later.

    0000051
    50 followersView on X

Explore more