Record summary

CVE-2021-24827 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Asgaros Forum

CVE List1.15.13 to < 1.15.13affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Asgaros Forum <1.15.13 - SQL InjectionCVSS 9.8

WordPress Asgaros Forum plugin before 1.15.13 is susceptible to SQL injection. The plugin does not validate and escape user input when subscribing to a topic before using it in a SQL statement. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation.

Remediation

Upgrade to the latest version of Asgaros Forum (1.15.13 or higher) to mitigate this vulnerability.

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicve2021cvewp-pluginasgaros-forumunauthwpscanwordpresswpsqliasgarosvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:asgaros:asgaros_forum:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3