CVE-2026-28562
Published Feb 28, 2026wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted id…
- evidence mentions
- 3
- Buzz score
- 23.9