HarborGuard / CVE
Back to search
HIGHCVE-2026-28562Published Modified CNA VulnCheck

CVE-2026-28562: wpForo Forum 2.4.14 SQL Injection via Topics ORDER BY Parameter

wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. Attackers exploit the wpfob parameter with CASE WHEN payloads to perform blind boolean extraction of credentials from the WordPress database.

Metrics

CVSS v4.0
8.8
Severity
HIGH
Fixed in
2.4.15
Affected Products
1

Fix available

2.4.15
Affected packages
  • gVectors Team / wpForo Forum
    < 2.4.15 (from 2.4)
    Fixed in 2.4.15
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N