Unauthenticated SQL Injection in wpForo Forum Plugin
CVE-2026-40798
9.3CRITICAL
What is CVE-2026-40798?
The wpForo Forum plugin for WordPress has a vulnerability that allows unauthenticated SQL Injection attacks, potentially compromising the security and integrity of the database. This issue exists in versions of the plugin up to 3.0.4, enabling attackers to manipulate database queries and access sensitive information without authentication.
Affected Version(s)
wpForo Forum <= 3.0.4