top of page
perceptive_background_267k.jpg

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recurs…

Published:

30 July 2026 at 00:00:00

Alert date:

30 July 2026 at 08:00:52

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to unauthenticated Remote Code Execution in all versions up to and including 8.9.0. The vulnerability exists in the recursive_html function, where the frontend save handler uses only a publicly emitted nonce with no authentication check. CAPTCHA validation can be bypassed by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later injected into an eval() call without sanitization. This allows unauthenticated attackers to execute arbitrary code on the server. Exploitation requires the [post_cf_form] shortcode to be present on at least one publicly accessible page, as the nonce and session ID are emitted to unauthenticated visitors. The combination of missing authentication, bypassable CAPTCHA, and unsanitized eval() input makes this a critical severity vulnerability.

Technical details

Mitigation steps:

Affected products:

Admin and Site Enhancements (ASE) Pro plugin for WordPress

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page