CVE-2026-73998: WordPress WP w3all phpBB plugin <= 3.0.5 - SQL Injection vulnerability
Published Aug 20, 2026
·Updated
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Affected Software
1 affected component
WordPress w3all phpBB<=3.0.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP w3all phpBB pluginto a version that resolves this vulnerability.Fixed in 3.0.6
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
WP w3all phpBB plugin versions 3.0.5 and earlier are affected.
2
What level of access does an attacker need, and what impact could exploitation have?
Exploitation is remotely reachable, requires low attack complexity, and requires Subscriber-level privileges; no user interaction is required. The reported impact includes high confidentiality impact, no integrity impact, and low availability impact, with scope changed.