Junglewise Threat Intelligence

CVE-2026-57636: Tomdever wpForo Forum SQL injection

CVE-2026-57636 · Severity: high · CVSS 8.5 · Published 2026-06-26

Executive brief

wpForo Forum is a popular discussion board plugin for WordPress websites. A security flaw allows users with 'Contributor' level access to execute unauthorized database commands, which could lead to the theft of sensitive information or disruption of the forum's operations.

Technical details

A SQL injection vulnerability exists in the wpForo Forum plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 3.0.9. An attacker with Contributor-level privileges can exploit this over the network without user interaction to interact directly with the underlying database. This can result in unauthorized data retrieval or minor availability impacts. The issue is addressed in version 3.1.0.

Affected products

  • Tomdever wpForo Forum <= 3.0.9

Timeline

  • 2026-05-11: other: Reported by researcher daroo
  • 2026-06-26: disclosed: Early warning sent to Patchstack customers
  • 2026-06-26: advisory: Public advisory published by Patchstack and NVD

References

Related threats