SQL Injection Vulnerability in Asgaros Forum Plugin for WordPress
CVE-2025-11452
What is CVE-2025-11452?
The Asgaros Forum plugin for WordPress is susceptible to SQL Injection vulnerabilities due to insufficient input escaping and preparation of the SQL query using the '$_COOKIE['asgarosforum_unread_exclude']' parameter. This flaw allows unauthenticated attackers to inject additional SQL queries, potentially enabling them to extract sensitive data from the database. All versions of the plugin prior to 3.1.0 are affected, highlighting the importance of updating to a secure version to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Asgaros Forum * <= 3.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved