wpForo Forum CVE-2026-1581 (CVSS 7.5): unauth time-based SQLi ≤2.4.14 — Previdian sees exploit attempts; patch 2.4.15+
Wordfence CNA CVE-2026-1581 (published 19 Feb 2026; CVSS 3.1 7.5 High AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N): unauthenticated time-based SQL injection in the WordPress wpForo Forum plugin via the ‘wpfob’ parameter in all versions up to and including 2.4.14 (insufficient escaping/preparation on SQL). Vendor changelog: 2.4.15 (10 Feb 2026) lists “Security: Vulnerability - Unauthenticated Time-Based SQL Injection” (current trunk Stable tag 3.2.2). UPDATE 1 Oct 2026: The Hacker News (bundled with SC backdoor coverage) cites Previdian telemetry — fewer than 20 exploitation attempts since 3 July 2026 from five unique IPs (Bulgaria, Switzerland, France, US, Yemen). Primary: Wordfence/MITRE CVE record + wpForo changelog; wire: THN 1 Oct.
- Product
- WordPress plugin: wpForo Forum (tomdever / gVectors)
- Versions
- Affected: all versions ≤ 2.4.14. Fixed: 2.4.15+ (changelog 10 Feb 2026); current Stable tag 3.2.2 on wordpress.org at desk check.
- CVSS
- (CVSS 3.1 High; Wordfence CNA)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - Exploited in Australia?
- unknown
- Patch to
- Upgrade wpForo Forum to 2.4.15 or later (prefer current 3.x Stable). Until patched: disable/remove the plugin or block unauthenticated access to endpoints accepting ‘wpfob’; hunt anomalous time-based SQLi probes in web logs since Jul 2026.
Primary: CVE.org / Wordfence CNA — CVE-2026-1581 wpForo unauth time-based SQLi · Vendor: WordPress.org — wpForo Forum plugin (changelog: 2.4.15 SQLi fix) · CVE: CVE-2026-1581 · The Hacker News — Previdian telemetry: wpForo CVE-2026-1581 exploit attempts since 3 Jul (1 Oct 2026)
