Back

CRITICAL

Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload

Published Nov 27, 2023

Description

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Nov 27, 2023
Updated Jun 5, 2025
Reserved Oct 16, 2023
CISA Vulnrichment
Updated Jul 11, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a