CVE-2026-28562Disclosure(gvectors / wpforo_forum)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. Attackers exploit the wpfob parameter with CASE WHEN payloads to perform blind boolean extraction of credentials from the WordPress database.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wpforo_forum

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
wpforo_forum

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-05: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-05: 102-2803-0103-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28562 (CVSS:8.8, HIGH) is Undergoing Analysis. wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause ..https://nvd.nist.gov/vuln/detail/CVE-2026-28562 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces that wpForo 2.4.14 contains a high‑severity (CVSS 8.8) unauthenticated SQL injection vulnerability (CVE‑2026‑28562) involving the Topics::get_topics() ORDER BY clause.

    0000027
    173 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28562 - wpForo Forum 2.4.14 SQL Injection via Topics ORDER BY Parameter Intel Report: https://ift.tt/X7F3mu0

    Post summary

    A new SQL injection vulnerability (CVE-2026-28562) in wpForo Forum 2.4.14 is disclosed, affecting the Topics ORDER BY parameter, with an Intel report linked for further details.

    0000042
    343 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28562 - High wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. A... https://www.thehackerwire.com/vulnerability/CVE-2026-28562/ https://t.co/vVgLjByzpa

    Post summary

    The post announces a high‑severity unauthenticated SQL injection in wpForo 2.4.14, providing technical details of the flaw but no PoC, exploit code, or patch information.

    0000073
    119 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgvectorswpforo_forum-wordpress-

Explore more