Impact
The Admin and Site Enhancements plugin for WordPress fails to enforce authentication, authorization, or nonce validation when handling a role‑restoration request. An attacker who has already had an administrator account demoted can send a request containing the reset‑for parameter to the vulnerable endpoint and has the account restored to the administrator role. This flaw allows unauthenticated privilege escalation to full site administration, providing the attacker complete control over the WordPress site. This issue is an incomplete fix of the earlier CVE-2024-43333 / CVE-2025-24648, which covered only one of the demotion paths.
Affected Systems
The vulnerability impacts the open‑source Admin and Site Enhancements (ASE) plugin and its pro edition, admin‑site‑enhancements‑pro, for WordPress, in all releases before version 8.8.4. Site operators using these plugins should verify the installed version and apply an update if the plugin is outdated.
Risk and Exploitability
The EPSS score of <1% and absence from CISA’s KEV catalog indicate a low yet nonzero likelihood of observed exploitation, but the high CVSS score of 8.1 reflects the severity of the privilege escalation. The vulnerability is exploitable without any prior credentials or special access; an attacker simply needs network reach to the site to craft an HTTP request containing the reset‑for parameter pointing to a demoted administrator account. Once the request is processed, the account is promoted to administrator, granting full control of the site.
OpenCVE Enrichment