Executive brief
WP w3all phpBB is a WordPress plugin that integrates phpBB forum functionality into WordPress sites. A SQL injection vulnerability in versions 3.0.5 and earlier allows attackers with subscriber-level account privileges to read, modify, or delete the entire site database, including user credentials and sensitive data, potentially leading to complete site compromise.
Technical details
The vulnerability is a SQL injection flaw in the WP w3all phpBB plugin that can be exploited by authenticated users with subscriber-level permissions. The root cause involves insufficient input validation in database queries. An attacker with subscriber access can inject malicious SQL code to read, modify, or delete arbitrary database records. The vulnerability is not network-unauthenticated; it requires a valid WordPress subscriber account. The vendor released a patched version 3.0.6 that addresses the injection flaw.
Affected products
- axew3.com WP w3all phpBB 3.0.5 and earlier
Timeline
- 2026-08-19: disclosed
- 2026-08-20: advisory