CVE-2026-1581
CVSS 7.5 HIGH: the wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all… EPSS 2% (77th percentile).
Vulnerabilities · 4h ago
Sucuri found attackers actively exploiting an unauthenticated SQL injection in the wpForo Forum WordPress plugin, tracked as CVE-2026-1581 and affecting versions up to 2.4.14. Sucuri says the payload is not a one-file backdoor but a self-healing implant it calls SC, built to keep coming back after cleanup.
The malware stores copies across WordPress files, the database, and shared memory, so deleting the obvious plugin file or uninstalling wpForo can leave another copy able to recreate it on the next page load. In plain terms, one layer can repopulate the others, which is why file-only remediation does not end the compromise.
For WordPress operators, the exposure sits wherever wpForo can write beyond the filesystem. If a site relies on plugin, cache, or shared-memory persistence, the cleanup problem outlives the vulnerable version and can turn a patched host back into an infected one if every storage plane is not accounted for.
CVSS 7.5 HIGH: the wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all… EPSS 2% (77th percentile).
1 source covering this story
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
SC WordPress malware rebuilds its backdoor from files, the database, and shared memory; fewer than 20 wpForo exploit attempts were seen since July 3.
Part of the PlainSec briefing for 2026-10-01