Unrated severityNVD Advisory· Published Aug 20, 2026
CVE-2026-19615
CVE-2026-19615
Description
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <9.0.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.