CVE-2023-5604: Asgaros Forum
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.
Affected products
- Asgaros Asgaros Forum: before 2.7.1 (fixed in 2.7.1)
Published 2023-11-27. Last modified 2026-06-17.