Junglewise Threat Intelligence

CVE-2026-57625: ASE Admin and Site Enhancements Pro unauthenticated XSS

CVE-2026-57625 · Severity: critical · CVSS 9.6 · Published 2026-07-02

Executive brief

Admin and Site Enhancements (ASE) Pro, a WordPress plugin used to manage and optimize site administration, contains a security flaw that allows unauthorized attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially take over administrative accounts, redirect users to malicious websites, or steal sensitive session information. This vulnerability is considered high risk because it does not require the attacker to have an account on the target site.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Admin and Site Enhancements (ASE) Pro plugin for WordPress due to improper neutralization of user-supplied input (CWE-79). The flaw allows an unauthenticated remote attacker to inject malicious web scripts. While the attack is unauthenticated, successful exploitation requires a privileged user to perform an action, such as clicking a malicious link or visiting a crafted page (User Interaction). Given the 'Scope: Changed' (S:C) and high impact on confidentiality, integrity, and availability, an attacker could potentially escalate privileges to a site administrator. The issue is resolved in version 8.8.6.

Affected products

  • ASE Admin and Site Enhancements (ASE) Pro <= 8.8.5

Timeline

  • 2026-06-18: other: Reported by Nguyen Ba Khanh
  • 2026-06-29: disclosed: Initial disclosure by Patchstack
  • 2026-07-02: advisory: NVD published CVE-2026-57625
  • 2026-08-06: patched: Fixed in version 8.8.6

References

Related threats