WpForo Forum WordPress plugin unauthenticated SQL injection SQL injection flaw (CVE-2026-1581)
Vulnerability
Summary
Hide ▲
Show ▼
Active exploitation of CVE-2026-1581 in the wpForo Forum WordPress plugin exposes sites running all versions up to 2.4.14 to unauthenticated SQL injection. Fewer than 20 exploitation attempts were observed since July 3, 2026, with probes arriving from five attacker IPs across multiple countries. The flaw is already being tested in the wild, creating direct risk of database access and broader WordPress site compromise.
Related Happenings
Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation Wave
H score87
First: 05.06.2026 11:38
Last: 05.06.2026 11:38
Sources 1
About this happening:
Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrar...
Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation WaveAbout this happening: Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrar...
CISA orders FCEB patching for CVE-2026-9082
Public Sector Action
H score70
First: 26.05.2026 11:46
Last: 26.05.2026 11:46
Sources 1
About this happening:
CISA added CVE-2026-9082 to the KEV Catalog and ordered FCEB agencies to patch Drupal by May 27, turning an actively exploited flaw into a mandatory federa...
CISA orders FCEB patching for CVE-2026-9082
Public Sector ActionAbout this happening: CISA added CVE-2026-9082 to the KEV Catalog and ordered FCEB agencies to patch Drupal by May 27, turning an actively exploited flaw into a mandatory federa...
CISA updates KEV entry for CVE-2026-1731
Public Sector Action
H score36
First: 20.02.2026 17:45
Last: 20.02.2026 17:45
Sources 1
About this happening:
CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
CISA updates KEV entry for CVE-2026-1731
Public Sector ActionAbout this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
Quiz and Survey Master SQL injection mitigation (CVE-2025-67987)
Advisory/Mitigation
H score61
First: 03.02.2026 18:15
Last: 03.02.2026 18:15
Sources 1
About this happening:
Patchstack published mitigation guidance for CVE-2025-67987, directing administrators to update Quiz and Survey Master to version 10.3.2 to close a SQL injection...
Quiz and Survey Master SQL injection mitigation (CVE-2025-67987)
Advisory/MitigationAbout this happening: Patchstack published mitigation guidance for CVE-2025-67987, directing administrators to update Quiz and Survey Master to version 10.3.2 to close a SQL injection...
Timeline
-
01.10.2026 17:37 2 articles · 1h ago
Previdian records fewer than 20 exploitation attempts against CVE-2026-1581
Exploitation ObservedPrevidian telemetry recorded fewer than 20 exploitation attempts against the unauthenticated SQL injection flaw in the wpForo Forum WordPress plugin, with activity observed since July 3, 2026 and probes originating from attacker IPs in Bulgaria, Switzerland, France, the U.S., and Yemen.
Show sources
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory — thehackernews.com — 01.10.2026 17:37
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory — thehackernews.com — 01.10.2026 17:37
-
01.10.2026 17:37 1 articles · 1h ago
Researchers disclose active exploitation of CVE-2026-1581 in wpForo Forum WordPress plugin
Initial DisclosureResearchers disclosed that the wpForo Forum WordPress plugin is affected by CVE-2026-1581, a high-severity unauthenticated SQL injection flaw with CVSS score 7.5 that is under active exploitation and affects versions up to and including 2.4.14.
Show sources
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory — thehackernews.com — 01.10.2026 17:37