CVE-2023-5604: Asgaros Forum

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.

Affected products

  • Asgaros Asgaros Forum: before 2.7.1 (fixed in 2.7.1)

Published 2023-11-27. Last modified 2026-06-17.