


Perceptive Security
SOC/SIEM Consultancy

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recurs…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 15:06:28
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to unauthenticated Remote Code Execution in all versions up to and including 8.9.0. The vulnerability exists in the recursive_html function where the frontend save handler lacks proper authentication checks and relies only on a publicly emitted nonce. CAPTCHA validation can be bypassed by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later injected into an eval() call without sanitization or identifier validation. This allows unauthenticated attackers to execute arbitrary code on the server. Exploitation requires the [post_cf_form] shortcode to be present on at least one publicly accessible page, as the nonce and session ID are emitted to unauthenticated visitors. The combination of missing authentication, bypassable CAPTCHA, and unsanitized eval() input makes this a critical severity vulnerability.
Technical details
Mitigation steps:
Affected products:
Admin and Site Enhancements (ASE) Pro plugin for WordPress 8.9.0 and below
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-16610
https://www.wordfence.com/threat-intel/vulnerabilities/id/2ef21a44-6d03-4197-b49c-d881f9831f46?source=cve
https://www.wpase.com/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
