SQL Injection Vulnerability in Asgaros Forum Plugin for WordPress
CVE-2025-11452
7.5HIGH
What is CVE-2025-11452?
The Asgaros Forum plugin for WordPress is susceptible to SQL Injection vulnerabilities due to insufficient input escaping and preparation of the SQL query using the '$_COOKIE['asgarosforum_unread_exclude']' parameter. This flaw allows unauthenticated attackers to inject additional SQL queries, potentially enabling them to extract sensitive data from the database. All versions of the plugin prior to 3.1.0 are affected, highlighting the importance of updating to a secure version to mitigate the risks associated with this vulnerability.
Affected Version(s)
Asgaros Forum * <= 3.1.0