Junglewise Threat Intelligence

CVE-2026-73998: WP w3all phpBB SQL injection in subscriber queries

CVE-2026-73998 · Severity: high · CVSS 8.5 · Published 2026-08-20

Executive brief

WP w3all phpBB is a WordPress plugin that integrates phpBB forum functionality into WordPress sites. A SQL injection vulnerability in versions 3.0.5 and earlier allows attackers with subscriber-level account privileges to read, modify, or delete the entire site database, including user credentials and sensitive data, potentially leading to complete site compromise.

Technical details

The vulnerability is a SQL injection flaw in the WP w3all phpBB plugin that can be exploited by authenticated users with subscriber-level permissions. The root cause involves insufficient input validation in database queries. An attacker with subscriber access can inject malicious SQL code to read, modify, or delete arbitrary database records. The vulnerability is not network-unauthenticated; it requires a valid WordPress subscriber account. The vendor released a patched version 3.0.6 that addresses the injection flaw.

Affected products

  • axew3.com WP w3all phpBB 3.0.5 and earlier

Timeline

  • 2026-08-19: disclosed
  • 2026-08-20: advisory

References

Related threats