Junglewise Threat Intelligence

CVE-2026-49769: gVectors wpForo Forum PHP object injection

CVE-2026-49769 · Severity: critical · CVSS 9.8 · Published 2026-06-15

Executive brief

wpForo Forum is a popular community forum plugin for WordPress websites. A critical security flaw allows unauthorized individuals to inject malicious code into the website's server. If exploited, this could lead to a total takeover of the website, theft of user data, or a complete shutdown of the forum services.

Technical details

The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 3.1.0. This vulnerability occurs due to the deserialization of untrusted data (CWE-502) without proper validation. An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present in the environment, the attacker can achieve remote code execution, perform SQL injection, or conduct arbitrary file deletion. The issue is resolved in version 3.1.1.

Affected products

  • gVectors Team wpForo Forum <= 3.1.0

Timeline

  • 2026-05-11: other: Vulnerability reported by researcher daroo
  • 2026-06-04: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: CVE published to NVD

References

Related threats