Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key
critical
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassabl...
- CVSS:
- 9.8
- Affected:
- up to 8.9.0
- Fixed in:
- 8.9.1
- Disclosed:
- Jul 29, 2026
CVE-2026-16610 on NVD →
Admin and Site Enhancements (ASE) Pro <= 8.8.5 - Unauthenticated Stored Cross-Site Scripting
high
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...
- CVSS:
- 7.2
- Affected:
- up to 8.8.5
- Fixed in:
- 8.8.6
- Disclosed:
- Jun 29, 2026
CVE-2026-57625 on NVD →
Admin and Site Enhancements <= 8.8.3 - Missing Authorization
medium
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'reset-for' endpoint in all versions up to, and including, 8.8.3. This makes it possible for unauthenticated attackers to reactivate a role they previously held.
- CVSS:
- 5.3
- Affected:
- up to 8.8.3
- Fixed in:
- 8.8.4
- Disclosed:
- Jun 26, 2026
CVE-2026-12083 on NVD →
Admin and Site Enhancements (ASE) Pro <= 7.6.2.1 - Authenticated (Subscriber+) Privilege Escalation
high
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 7.6.2.1. This is due to the plugin not properly restricting user's ability to utilize the “View Admin as Role” feature. This makes it possible for authenticated attackers, with Subs...
- CVSS:
- 7.5
- Affected:
- up to 7.6.2.1
- Fixed in:
- 7.6.3
- Disclosed:
- Feb 3, 2025
CVE-2024-43333 on NVD →
Admin and Site Enhancements (ASE) Pro <= 7.6.1.1 - Missing Authorization
medium
The admin-site-enhancements-pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.6.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 7.6.1.1
- Fixed in:
- 7.6.3
- Disclosed:
- Jan 24, 2025
CVE-2025-24653 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database