Description
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57897 | The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution. |
References
History
Thu, 05 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:asgaros:asgaros_forum:-:*:*:*:*:wordpress:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-05T14:03:11.558Z
Reserved: 2023-10-16T18:22:09.384Z
Link: CVE-2023-5604
Updated: 2024-08-02T08:07:32.119Z
Status : Modified
Published: 2023-11-27T17:15:09.030
Modified: 2024-11-21T08:42:06.460
Link: CVE-2023-5604
No data.
OpenCVE Enrichment
No data.
EUVD