VYPR

Admin and Site Enhancements (ASE) Pro

by WordPress

CVEs (4)

  • CVE-2024-43333HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect Privilege Assignment vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.2.1.

  • CVE-2025-24653MedJan 27, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.1.1.

  • CVE-2026-16610CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no…

  • CVE-2026-57625CriJul 2, 2026
    risk 0.00cvss 9.6epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.