Cross-Site Request Forgery in Asgaros Forum Plugin for WordPress
CVE-2025-12901
4.3MEDIUM
What is CVE-2025-12901?
The Asgaros Forum plugin for WordPress has a vulnerability in the set_subscription_level() function, which lacks proper nonce validation. This flaw allows unauthorized attackers to perform CSRF attacks, enabling them to alter subscription settings of authenticated users. By tricking a logged-in user into clicking a malicious link, attackers can execute actions without the user's consent, compromising user accounts and leading to inappropriate access rights.
Affected Version(s)
Asgaros Forum * <= 3.2.1