SQL Injection Vulnerability in Asgaros Forum Plugin for WordPress
CVE-2025-11452

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 November 2025

What is CVE-2025-11452?

The Asgaros Forum plugin for WordPress is susceptible to SQL Injection vulnerabilities due to insufficient input escaping and preparation of the SQL query using the '$_COOKIE['asgarosforum_unread_exclude']' parameter. This flaw allows unauthenticated attackers to inject additional SQL queries, potentially enabling them to extract sensitive data from the database. All versions of the plugin prior to 3.1.0 are affected, highlighting the importance of updating to a secure version to mitigate the risks associated with this vulnerability.

Affected Version(s)

Asgaros Forum * <= 3.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Naoya Takahashi
.
CVE-2025-11452 : SQL Injection Vulnerability in Asgaros Forum Plugin for WordPress