CVE-2026-28562
HIGHwpForo Forum 2.4.0-2.4.14 - Unauthenticated SQL Injection via Topics ORDER BY Parameter
Title source: llmDescription
wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. Attackers exploit the wpfob parameter with CASE WHEN payloads to perform blind boolean extraction of credentials from the WordPress database.
References (3)
Core 3
Core References
Product product
https://wordpress.org/plugins/wpforo/
Product patch
https://wordpress.org/plugins/wpforo/#developers
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/wpforo-sql-injection-via-topics-order-by-parameter
Scores
CVSS v3
8.2
EPSS
0.0043
EPSS Percentile
34.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (3)
gvectors/wpforo_forum
2.4.0 - 2.4.15
gVectors Team/wpForo Forum
2.4 - 2.4.15
gVectors Team/wpForo Forum
2.4.15
Published
Feb 28, 2026
Tracked Since
Mar 01, 2026