The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-57897 The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 05 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:asgaros:asgaros_forum:-:*:*:*:*:wordpress:*:*
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-06-05T14:03:11.558Z

Reserved: 2023-10-16T18:22:09.384Z

Link: CVE-2023-5604

cve-icon Vulnrichment

Updated: 2024-08-02T08:07:32.119Z

cve-icon NVD

Status : Modified

Published: 2023-11-27T17:15:09.030

Modified: 2024-11-21T08:42:06.460

Link: CVE-2023-5604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.