logo

WordPress ASE Plugin Vulnerability Threatens Site Security

ID: 743ea8de-6436-527f-957d-f4ece3d688c5

STIX ID: report--743ea8de-6436-527f-957d-f4ece3d688c5

Feed Name: Infosecurity Magazine (News)

Threat Score
60/100

Date Published: 2025-02-06

Date Updated: 2026-04-22

...
...

A privilege-escalation vulnerability in the Admin and Site Enhancements (ASE) WordPress plugin (<= 7.6.2.1) allowed authenticated users to restore previously higher roles via the “View Admin as Role” feature because role restoration relied only on a nonce check and lacked proper permission verification; the issue (CVE-2025-24648 / CVE-2024-43333) affecting ~100,000 installations was patched in version 7.6.3 and administrators are urged to update, disable the feature if unnecessary, and audit roles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.