CVE Database
/

CVE-2023-5604

Back to search

CVE-2023-5604

Published: Nov 27, 2023

Modified: Jun 5, 2025

PUBLISHED

Description

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.

VendorProductVersions

Unknown

Asgaros Forum

affected
0 - < 2.7.1

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now