SQL Injection Vulnerability in wpForo Forum Plugin for WordPress
CVE-2026-5097

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 August 2026

What is CVE-2026-5097?

The wpForo Forum plugin for WordPress suffers from an SQL Injection vulnerability via the 'referer' parameter due to inadequate input sanitization and improper preparation of SQL queries. This security flaw allows unauthenticated attackers to insert additional SQL statements into existing queries, leading to potential exposure of sensitive information stored in the database. Users of wpForo Forum versions up to and including 2.4.17 are advised to take immediate action by updating to secure their applications against possible exploitation.

Affected Version(s)

wpForo Forum 0 <= 2.4.17

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Leonid Semenenko (lsemenenko)
.