wpForo Forum WordPress plugin <= 2.4.14 contains a time-based SQL injection caused by insufficient escaping of the 'wpfob' parameter, letting unauthenticated attackers extract sensitive database information.
id: CVE-2026-1581
info:
name: wpForo Forum <= 2.4.14 - SQL Injection
author: Shivam Kamboj
se
...