Admin and Site Enhancements (ASE) < 9.0.1 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 9.0.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 9.0.1
- Fixed in:
- 9.0.1
- Disclosed:
- Aug 21, 2026
CVE-2026-19615 on NVD →
Admin and Site Enhancements <= 8.8.3 - Missing Authorization
medium
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'reset-for' endpoint in all versions up to, and including, 8.8.3. This makes it possible for unauthenticated attackers to reactivate a role they previously held.
- CVSS:
- 5.3
- Affected:
- up to 8.8.3
- Fixed in:
- 8.8.4
- Disclosed:
- Jun 26, 2026
CVE-2026-12083 on NVD →
Admin and Site Enhancements (ASE) <= 8.4.0 - Missing Authorization
medium
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.4.0. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 8.4.0
- Fixed in:
- 8.4.1
- Disclosed:
- Feb 27, 2026
CVE-2026-32423 on NVD →
Admin and Site Enhancements (ASE) <= 7.6.2.1 - Authenticated (Subscriber+) Privilege Escalation
high
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.6.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
- CVSS:
- 8.8
- Affected:
- up to 7.6.2.1
- Fixed in:
- 7.6.3
- Disclosed:
- Jan 20, 2026
CVE-2025-24648 on NVD →
Admin and Site Enhancements (ASE) <= 8.0.8 - Missing Authorization
medium
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.0.8. This makes it possible for authenticated attackers, with Author-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 8.0.8
- Fixed in:
- 8.1.0
- Disclosed:
- Dec 15, 2025
CVE-2025-64255 on NVD →
Admin and Site Enhancements (ASE) [admin-site-enhancements] <= 8.0.8 (unfixed)
unknown
[en] Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 8.0.8.
- Affected:
- up to 8.0.8
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-64255 on NVD →
Admin and Site Enhancements <= 7.9.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG
medium
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to...
- CVSS:
- 5.4
- Affected:
- up to 7.9.7
- Fixed in:
- 7.9.8
- Disclosed:
- Sep 1, 2025
CVE-2025-9487 on NVD →
Admin and Site Enhancements (ASE) [admin-site-enhancements] < 7.6.10
unknown
[en] The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection offered via a crafted request
- Affected:
- up to 7.6.10
- Fixed in:
- 7.6.10
- Disclosed:
- Apr 28, 2025
CVE-2024-13688 on NVD →
Admin and Site Enhancements (ASE) <= 7.6.9 - Password Protection Bypass
medium
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Password Protection Bypass in all versions up to, and including, 7.6.9. This is due to the plugin using a hardcoded password for password protection. This makes it possible for unauthenticated attackers to access a password protected site.
- CVSS:
- 5.3
- Affected:
- up to 7.6.9
- Fixed in:
- 7.6.10
- Disclosed:
- Apr 7, 2025
CVE-2024-13688 on NVD →
Admin and Site Enhancements (ASE) [admin-site-enhancements] < 7.6.10
unknown
[en] The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value to bypass the login limit feature in the Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10.
- Affected:
- up to 7.6.10
- Fixed in:
- 7.6.10
- Disclosed:
- Mar 4, 2025
CVE-2024-13685 on NVD →
Admin and Site Enhancements (ASE) <= 7.6.9 - IP Spoofing to Limit Login Attempt Bypass
medium
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 7.6.9 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to bypass login limit restrictions.
- CVSS:
- 5.3
- Affected:
- up to 7.6.9
- Fixed in:
- 7.6.10
- Disclosed:
- Feb 11, 2025
CVE-2024-13685 on NVD →
Admin and Site Enhancements (ASE) [admin-site-enhancements] < 7.6.3
unknown
[en] Incorrect Privilege Assignment vulnerability in wpase.com Admin and Site Enhancements (ASE) allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE): from n/a through 7.6.2.1.
- Affected:
- up to 7.6.3
- Fixed in:
- 7.6.3
- Disclosed:
- Feb 4, 2025
CVE-2025-24648 on NVD →
Admin and Site Enhancements (ASE) Pro <= 7.6.2.1 - Authenticated (Subscriber+) Privilege Escalation
high
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 7.6.2.1. This is due to the plugin not properly restricting user's ability to utilize the “View Admin as Role” feature. This makes it possible for authenticated attackers, with Subs...
- CVSS:
- 7.5
- Affected:
- up to 7.6.2.1
- Fixed in:
- 7.6.3
- Disclosed:
- Feb 3, 2025
CVE-2024-43333 on NVD →
Admin and Site Enhancements (ASE) [admin-site-enhancements] < 7.6.3
unknown
[en] Incorrect Privilege Assignment vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.2.1.
- Affected:
- up to 7.6.3
- Fixed in:
- 7.6.3
- Disclosed:
- Feb 3, 2025
CVE-2024-43333 on NVD →
Admin and Site Enhancements (ASE) <= 7.6.2 - Missing Authorization
low
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 3.1
- Affected:
- up to 7.6.2
- Fixed in:
- 7.6.3
- Disclosed:
- Jan 24, 2025
CVE-2025-24649 on NVD →
Admin and Site Enhancements (ASE) [admin-site-enhancements] < 7.6.3
unknown
[en] Missing Authorization vulnerability in wpase.com Admin and Site Enhancements (ASE) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhancements (ASE): from n/a through 7.6.2.
- Affected:
- up to 7.6.3
- Fixed in:
- 7.6.3
- Disclosed:
- Jan 24, 2025
CVE-2025-24649 on NVD →
Admin and Site Enhancements (ASE) [admin-site-enhancements] < 7.5.2
unknown
[en] The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above...
- Affected:
- up to 7.5.2
- Fixed in:
- 7.5.2
- Disclosed:
- Nov 12, 2024
CVE-2024-10790 on NVD →
Admin and Site Enhancements (ASE) <= 7.5.1 - Authenticated Stored Cross-Site Scripting via SVG
medium
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to...
- CVSS:
- 5.4
- Affected:
- up to 7.5.1
- Fixed in:
- 7.5.2
- Disclosed:
- Nov 11, 2024
CVE-2024-10790 on NVD →
Admin and Site Enhancements (ASE) [admin-site-enhancements] < 5.8.0
unknown
[en] Improper Authentication vulnerability in wpase Admin and Site Enhancements (ASE) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Admin and Site Enhancements (ASE): from n/a through 5.7.1.
- Affected:
- up to 5.8.0
- Fixed in:
- 5.8.0
- Disclosed:
- Jun 4, 2024
CVE-2023-46630 on NVD →
Admin and Site Enhancements (ASE) <= 5.7.1 - Password Protection Mode Security Feature Bypass
high
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to security feature bypass in all versions up to, and including, 5.7.1. This is due to a flawed authentication mechanism within the maybe_process_login function. This makes it possible for unauthenticated attackers to bypass the Password Protectio...
- CVSS:
- 7.5
- Affected:
- up to 5.7.1
- Fixed in:
- 5.8.0
- Disclosed:
- Oct 25, 2023
CVE-2023-46630 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database