Impact
This flaw allows an attacker to impersonate a legitimate user within the Asgaros Forum plugin, which can let them act with the spoofed account's privileges. Based on the description, it is inferred that the attacker could upload files or perform other actions normally limited to the trusted account, potentially enabling further site compromise or misuse of the forum.
Affected Systems
All releases of the Asgaros Forum plugin for WordPress up to and including version 3.0.0 are affected. The CVE documentation states the issue applies from an unspecified earliest version through <=3.0.0. Based on the information, it is inferred that any version newer than 3.0.0 is not impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS value of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to send crafted requests to the forum to spoof the identity of a known user, which could be performed remotely via the web interface without pre‑existing credentials for the impersonated account.
OpenCVE Enrichment
EUVD