CRITICAL
Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload
Published Nov 27, 2023
9.8
CRITICALCVSS 3.1
EPSS 1.96%
Description
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.
Affected products
- Vendor n/a Product Asgaros Forum Defaultunaffected
- Version 0StatusaffectedConstraints<2.7.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Asgaros Forum | unaffected |
|
- < 2.7.1
-
- Version 0StatusaffectedConstraints<2.71
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Asgaros | Asgaros Forum | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (1)
- https://wpscan.com/vulnerability/4ce69d71-87bf-4d95-90f2-63d558c78b69 exploitvdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://wpscan.com/vulnerability/4ce69d71-87bf-4d95-90f2-63d558c78b69 | exploitvdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Nov 27, 2023
Updated Jun 5, 2025
Reserved Oct 16, 2023
Link CVE-2023-5604
CISA Vulnrichment
Updated Jul 11, 2024