Asgaros Forum
Asgaros Forum has 12 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; all 12 are fixed as of September 2026. Their average CVSS score is 6.9, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 4 high. 2025 was the busiest year with 4 disclosures.
The most common weakness is SQL Injection, behind 4 of the records (33%). Other recurring categories include Cross-Site Request Forgery (CSRF), Cross-Site Scripting.
Every one of the 12 issues recorded for Asgaros Forum has a vendor fix available, so running the current release closes all known holes.
12 independent researchers contributed these findings, one record each. Asgaros Forum is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-22284Asgaros Forum <= 2.7.2 - Unauthenticated PHP Object Injection in prepare_unread_status
Read the full analysisVulnerability Records

Asgaros Forum
Author
Asgaros
Asgaros Forum is the perfect WordPress plugin if you want to extend your website with a lightweight and feature-rich discussion board. It is easy to set up, super fast and perfectly integrated into WordPress. Support, Demo & Documentation Support & Demo Documentation Features Simple Content Management Profiles & Members List Notifications & Feeds Powerful Editor SEO-friendly Reactions Uploads Search Polls Widgets Statistics Guest Postings Approval, Banning & Reporting Moderators, Permissions & Usergroups Customizable Responsive Theme Multilingualism Multiple Instances Multisite Compatibility myCRED Integration Installation A new forum-page is automatically created during the installation Add this page to your menu so your users can access your forum Thats all!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C