CVE-2026-1581
CVSS 7.5 HIGH: the wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all… EPSS 2% (77º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Sucuri ha trovato sfruttamenti attivi contro il plugin wpForo Forum per WordPress: una SQL injection non autenticata, CVE-2026-1581, colpisce le versioni fino alla 2.4.14. Il payload associato al backdoor SC non resta in un solo punto. Si replica tra file, database e shared memory, e ricostruisce ciò che viene rimosso.
In pratica, cancellare il file più evidente o disinstallare il plugin non basta. Se una copia sopravvive nel database, nella cache o in un segmento di memoria condivisa, alla richiesta successiva può rigenerare le altre e riportare il sito allo stato compromesso.
Per chi gestisce WordPress con wpForo, il problema non è solo la falla iniziale. La compromissione può sopravvivere alla bonifica standard e trasferire il contenimento da un singolo artefatto su disco a più livelli di storage sul server.
1 fonte · 5 ore fa
CVSS 7.5 HIGH: the wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all… EPSS 2% (77º percentile).
The Hacker News
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
SC WordPress malware rebuilds its backdoor from files, the database, and shared memory; fewer than 20 wpForo exploit attempts were seen since July 3.
originalePart of the PlainSec briefing for 2026-10-01
Every edition of this story: WordPress reinfetta il backdoor anche dopo la pulizia