PHP Object Injection Vulnerability in wpForo Forum Product by WordPress
CVE-2026-49769
9.8CRITICAL
What is CVE-2026-49769?
An unauthenticated PHP Object Injection vulnerability exists in wpForo Forum versions 3.1.0 and earlier. This issue allows attackers to inject malicious objects into the PHP code, potentially leading to unauthorized actions and the compromise of sensitive information. It is crucial for users of affected versions to take immediate action to mitigate the risks associated with this vulnerability.
Affected Version(s)
wpForo Forum <= 3.1.0