Impact
The vulnerability is a missing authorization check in the Admin and Site Enhancements (ASE) plugin for WordPress, which could allow an attacker to perform actions beyond their intended permissions, potentially compromising the confidentiality and integrity of site data.
Affected Systems
WordPress sites using the Bowo Admin and Site Enhancements (ASE) plugin version 7.6.2 or earlier are affected. The plugin is widely used and is part of the WordPress ecosystem.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% shows a very low exploitation probability. The vulnerability is not in the CISA KEV catalog. Based on the description, the likely attack vector is a web-based request to the plugin’s administrative endpoints that lack proper access checks, potentially enabling privilege escalation. The conditions for exploitation are minimal and can be carried out by an attacker with any user role or even an unauthenticated user if the endpoint is publicly reachable.
OpenCVE Enrichment
EUVD