Junglewise Threat Intelligence

CVE-2026-40798: wpForo wpForo Forum unauthenticated SQL injection

CVE-2026-40798 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Technologies: gVectors Team wpForo Forum. Vendors: gVectors Team.

Executive brief

wpForo Forum is a popular community forum plugin for WordPress websites. A critical security flaw allows unauthorized individuals to interact directly with the website's database without needing a password or account. This could lead to the theft of sensitive user information, exposure of private data, or disruption of the website's operations.

Technical details

A SQL injection vulnerability exists in the wpForo Forum plugin for WordPress (versions <= 3.0.4) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to unauthenticated remote attackers over the network, requiring no user interaction. By sending specially crafted requests, an attacker can execute arbitrary SQL queries against the backend database. This can result in the extraction of sensitive data, such as user credentials and configuration details, or cause limited service disruption. The issue is resolved in version 3.0.5.

Affected products

  • wpForo wpForo Forum <= 3.0.4

Timeline

  • 2026-04-07: other: Reported by Nguyen Ba Khanh
  • 2026-05-07: disclosed: Initial disclosure by Patchstack
  • 2026-05-07: patched: Version 3.0.5 released to address the vulnerability
  • 2026-06-15: advisory: NVD publication date

References

Related threats