Asgaros Forum <= 3.0.0 - Authenticated (Subscriber+) Authorization Bypass

2025-04-07 00:00
20kilograma

Strategic Overview

Status
Patched in 3.1.0
Affected PluginAsgaros Forum
Affected Version<= 3.0.0
CVSS4.3Medium
CVECVE-2025-32227
View all Asgaros Forum vulnerabilities

Vulnerability Overview

The Asgaros Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to bypass something related to file numbers, though it is not clear exactly what this means from the original CNAs report.

Technical Analysis

REMEDIATION: Update to version 3.1.0, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C