CVE-2023-5604: Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-5604.
What is the severity of CVE-2023-5604?
The severity of CVE-2023-5604 is critical.
What is the affected software of CVE-2023-5604?
The affected software of CVE-2023-5604 is Asgaros Forum WordPress plugin version up to 2.7.1.
What is the description of CVE-2023-5604?
CVE-2023-5604 is a vulnerability in the Asgaros Forum WordPress plugin before 2.7.1 that allows unauthenticated users to upload dangerous files, potentially leading to remote code execution.
How can I fix CVE-2023-5604?
To fix CVE-2023-5604, update the Asgaros Forum WordPress plugin to version 2.7.1 or above.