Impact
The WordPress Admin and Site Enhancements (ASE) plugin contains a missing authorization flaw, enabling authenticated users with insufficient permissions to execute privileged actions. This allows an attacker to access or modify administrative settings and content that should be restricted, compromising the integrity and confidentiality of the site.
Affected Systems
The vulnerability affects the Bowo Admin and Site Enhancements (ASE) plugin in WordPress. All plugin releases from the initial version through 8.0.8 are vulnerable. The system impacted is any WordPress installation running this plugin version.
Risk and Exploitability
The CVSS score of 2.7 indicates a low baseline severity, and the EPSS score of less than 1% shows that current exploitation activity is very unlikely. The vulnerability is not listed in the CISA KEV catalog. The official description does not specify a precise attack vector, but the flaw appears in the plugin’s web interface, so the most probable exploitation path involves issuing crafted HTTP requests to administrative endpoints that check for missing authorization. An attacker would need to be authenticated to the site, though the privileged action could be gained even by users with minimal access rights if proper role checks are not performed.
OpenCVE Enrichment