Description
The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API exposes.
Published: 2026-07-06
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Admin and Site Enhancements plugin for WordPress fails to enforce authentication, authorization, or nonce validation when handling a role‑restoration request. An attacker who has already had an administrator account demoted can send a request containing the reset‑for parameter to the vulnerable endpoint and has the account restored to the administrator role. This flaw allows unauthenticated privilege escalation to full site administration, providing the attacker complete control over the WordPress site. This issue is an incomplete fix of the earlier CVE-2024-43333 / CVE-2025-24648, which covered only one of the demotion paths.

Affected Systems

The vulnerability impacts the open‑source Admin and Site Enhancements (ASE) plugin and its pro edition, admin‑site‑enhancements‑pro, for WordPress, in all releases before version 8.8.4. Site operators using these plugins should verify the installed version and apply an update if the plugin is outdated.

Risk and Exploitability

The EPSS score of <1% and absence from CISA’s KEV catalog indicate a low yet nonzero likelihood of observed exploitation, but the high CVSS score of 8.1 reflects the severity of the privilege escalation. The vulnerability is exploitable without any prior credentials or special access; an attacker simply needs network reach to the site to craft an HTTP request containing the reset‑for parameter pointing to a demoted administrator account. Once the request is processed, the account is promoted to administrator, granting full control of the site.

Generated by OpenCVE AI on July 26, 2026 at 20:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ASE or admin‑site‑enhancements‑pro plugin to version 8.8.4 or later.
  • If upgrading immediately is not possible, block or remove the role‑restoration endpoint that processes the reset‑for parameter using network firewall rules or server‑side filters.
  • Implement proper authentication, authorization, and nonce checks around role‑management functionality, following best practices for access control as outlined by CWE-284.

Generated by OpenCVE AI on July 26, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 17 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 15 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 13 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 13 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 12 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 11 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 11 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 10 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 09 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 08 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 07 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 07 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 06 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API exposes.
Title Admin and Site Enhancements < 8.8.4 - Unauthenticated Administrator-Role Restoration via reset-for Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-06T12:00:32.159Z

Reserved: 2026-06-12T13:04:18.229Z

Link: CVE-2026-12083

cve-icon Vulnrichment

Updated: 2026-07-06T12:00:28.985Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T21:00:04Z

Weaknesses