CVE-2026-1581
CVSS 7.5 HIGH: the wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all… EPSS 2% (77th percentile).
Vulnerabilities & Exploits · Web App Attack
Sucuri found attackers actively exploiting an unauthenticated SQL injection in the wpForo Forum WordPress plugin, tracked as CVE-2026-1581 and affecting versions up to 2.4.14. Sucuri says the payload is not a one-file backdoor but a self-healing implant it calls SC, built to keep coming back after cleanup.
The malware stores copies across WordPress files, the database, and shared memory, so deleting the obvious plugin file or uninstalling wpForo can leave another copy able to recreate it on the next page load. In plain terms, one layer can repopulate the others, which is why file-only remediation does not end the compromise.
For WordPress operators, the exposure sits wherever wpForo can write beyond the filesystem. If a site relies on plugin, cache, or shared-memory persistence, the cleanup problem outlives the vulnerable version and can turn a patched host back into an infected one if every storage plane is not accounted for.
1 source · 5h ago
CVSS 7.5 HIGH: the wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all… EPSS 2% (77th percentile).
The Hacker News
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
SC WordPress malware rebuilds its backdoor from files, the database, and shared memory; fewer than 20 wpForo exploit attempts were seen since July 3.
originalPart of the PlainSec briefing for 2026-10-01
Every edition of this story: wpForo Backdoor Keeps Rebuilding After Cleanup