← Back to browse · API

CVE-2023-5604

Severity
CRITICAL
CVSS
9.8
EPSS
0.01964
Risk score
39.89
CISA KEV
No
PoC
No
Published
2023-11-27
Modified
2025-06-05
First seen
2026-08-07
Aliases
EUVD-2023-57897, GHSA-7862-QCXG-7H4C
Products
Asgaros:Asgaros Forum 0 <2.7.1
Sources
euvd EUVD-2023-57897

Description

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.

References