Vulnerabilities & Exploits · Web App Attack

wpForo Backdoor Keeps Rebuilding After Cleanup

Sucuri found attackers actively exploiting an unauthenticated SQL injection in the wpForo Forum WordPress plugin, tracked as CVE-2026-1581 and affecting versions up to 2.4.14. Sucuri says the payload is not a one-file backdoor but a self-healing implant it calls SC, built to keep coming back after cleanup.

The malware stores copies across WordPress files, the database, and shared memory, so deleting the obvious plugin file or uninstalling wpForo can leave another copy able to recreate it on the next page load. In plain terms, one layer can repopulate the others, which is why file-only remediation does not end the compromise.

For WordPress operators, the exposure sits wherever wpForo can write beyond the filesystem. If a site relies on plugin, cache, or shared-memory persistence, the cleanup problem outlives the vulnerable version and can turn a patched host back into an infected one if every storage plane is not accounted for.

1 source · 5h ago

CVE-2026-1581

NVD KEV

CVSS 7.5 HIGH: the wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all… EPSS 2% (77th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-10-01

Every edition of this story: wpForo Backdoor Keeps Rebuilding After Cleanup

More from today