CVE-2026-39779: WordPress Asgaros Forum plugin <= 3.4.0 - Broken Access Control vulnerability
Published Oct 9, 2026
·Updated
Missing Authorization vulnerability in Asgaros Asgaros Forum asgaros-forum allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asgaros Forum: from n/a through 3.4.0.
Affected Software
1 affected component
Asgaros Asgaros Forum<=3.4.0
Event History
Oct 9, 2026
CVE Published
via MITRE·11:44 AM
Data Sourced
via MITRE·11:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges and can exploit it remotely without user interaction. The vulnerability affects Asgaros Forum versions through 3.4.0.
2
What is the potential impact?
The reported impact is limited to confidentiality: an attacker may gain unauthorized access to information. No integrity or availability impact is indicated.