Impact
A missing authorization flaw in the WordPress Admin and Site Enhancements (ASE) Pro plugin enables attackers to perform actions normally reserved for privileged users. Classified as CWE‑862, the weakness means the plugin fails to enforce proper permission checks, allowing an unauthorized actor to read or modify critical site settings, potentially exposing configuration data or facilitating further exploitation.
Affected Systems
The vulnerability applies to the NotFound Admin and Site Enhancements (ASE) Pro WordPress plugin in all releases up through version 7.6.1.1. Any WordPress site running a vulnerable version is at risk until the plugin is upgraded.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS of less than 1% reflects a low probability of exploitation today. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the plugin’s administrative interface, where a user without proper privileges can invoke routes that bypass authorization and elevate their permissions on the WordPress site.
OpenCVE Enrichment
EUVD