Medium severity6.8NVD Advisory· Published Aug 20, 2026· Updated Aug 26, 2026
CVE-2026-19615
CVE-2026-19615
Description
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <9.0.1
Patches
Vulnerability mechanics
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)Wordfence Blog · Aug 27, 2026