Please or Register to create posts and topics.

Cross-Site Request Forgery (CSRF) vulnerability

Getting alerts that there is a security issue with 2.1.0?

WordPress Asgaros Forum plugin <= 2.1.0 – Cross-Site Request Forgery (CSRF) vulnerability

https://patchstack.com/database/vulnerability/asgaros-forum/wordpress-asgaros-forum-plugin-2-1-0-cross-site-request-forgery-csrf-vulnerability?_a_id=110

Andreas and nopjackson have reacted to this post.
Andreasnopjackson

I guess Thomas is already aware, but the plugin has even been temporarily removed by WordPress…
https://fr.wordpress.org/plugins/asgaros-forum/

icentrics has reacted to this post.
icentrics

Yes same here

 

Category:PLUGIN

Versions-Affected:<= 2.1.0

Type:Cross Site Request Forgery

Severity:MEDIUM

Description:Cross-Site Request Forgery (CSRF) vulnerability discovered by Dhakal Ananda (Patchstack Alliance) in the WordPress Asgaros Forum plugin (versions <= 2.1.0).

icentrics and nopjackson have reacted to this post.
icentricsnopjackson

Did you ever find or create a fix for the CSRF issue, if so, can you share? Thanks-

Hello

This issue should be fully fixed. I still get complains that the issue is still there, but I never got any additional details. Also the plugin got a security audit from the WordPress team and I am not aware of any additional security issues.

If you want to support the development of Asgaros Forum, you can leave a good review or donate. Thank you very much!