Vulnerability Description
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asgaros | Asgaros Forum | < 2.7.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/4ce69d71-87bf-4d95-90f2-63d558c78b69ExploitThird Party Advisory
- https://wpscan.com/vulnerability/4ce69d71-87bf-4d95-90f2-63d558c78b69ExploitThird Party Advisory
FAQ
What is CVE-2023-5604?
CVE-2023-5604 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload ...
How severe is CVE-2023-5604?
CVE-2023-5604 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-5604?
Check the references section above for vendor advisories and patch information. Affected products include: Asgaros Asgaros Forum.