top of page
perceptive_background_267k.jpg

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recurs…

Published:

30 juli 2026 om 00:00:00

Alert date:

30 juli 2026 om 17:06:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to unauthenticated Remote Code Execution in all versions up to and including 8.9.0. The vulnerability exists in the recursive_html function where the frontend save handler lacks proper authentication checks and relies only on a publicly emitted nonce. CAPTCHA validation can be bypassed by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later injected into an eval() call without sanitization or identifier validation. This allows unauthenticated attackers to execute arbitrary code on the server. Exploitation requires the [post_cf_form] shortcode to be present on at least one publicly accessible page, as the nonce and session ID are emitted to unauthenticated visitors. The combination of missing authentication, bypassable CAPTCHA, and unsanitized eval() input makes this a critical severity vulnerability.

Technical details

Mitigation steps:

Affected products:

Admin and Site Enhancements (ASE) Pro plugin for WordPress 8.9.0 and below

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page