WordPress ASE Plugin Vulnerability Threatens Site Security
ID: 743ea8de-6436-527f-957d-f4ece3d688c5
STIX ID: report--743ea8de-6436-527f-957d-f4ece3d688c5
Feed Name: Infosecurity Magazine (News)
A privilege-escalation vulnerability in the Admin and Site Enhancements (ASE) WordPress plugin (<= 7.6.2.1) allowed authenticated users to restore previously higher roles via the “View Admin as Role” feature because role restoration relied only on a nonce check and lacked proper permission verification; the issue (CVE-2025-24648 / CVE-2024-43333) affecting ~100,000 installations was patched in version 7.6.3 and administrators are urged to update, disable the feature if unnecessary, and audit roles.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
