CVE-2026-57636: WordPress wpForo Forum plugin <= 3.0.9 - SQL Injection vulnerability
Published Jun 26, 2026
·Updated
Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.
Affected Software
1 affected component
wpForo wpForo Forum<=3.0.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress wpForo Forum Pluginto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Jun 26, 2026
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57636?
The severity of CVE-2026-57636 is rated as high with a score of 8.5.
2
How do I fix CVE-2026-57636?
To fix CVE-2026-57636, update the wpForo Forum plugin to version 3.1.0 or later.
3
What type of vulnerability is CVE-2026-57636?
CVE-2026-57636 is an SQL Injection vulnerability affecting the wpForo Forum plugin.
4
What versions of wpForo Forum are affected by CVE-2026-57636?
CVE-2026-57636 affects wpForo Forum versions up to and including 3.0.9.
5
What impact does CVE-2026-57636 have on security?
CVE-2026-57636 allows for potential data manipulation or unauthorized access to the database through SQL injection.