Impact
The ASE WordPress plugin fails to sanitise SVG files on routes that accept uploads, enabling a user with upload permissions to store a malicious SVG containing JavaScript. When another user opens the SVG, the script runs in the victim’s browser, potentially exfiltrating credentials or performing actions on the user’s behalf. Based on the description, the likely attack vector is an authenticated upload via the XML‑RPC endpoint; the vulnerability is limited to users who are granted upload rights by the site owner. The impact is confined to the browser context of a browsing user; there is no direct remote code execution on the server. The CVSS score of 6.8, an EPSS below 1% and absence from the KEV list suggest moderate severity and low current exploitation probability, though any user who views the stored SVG is at risk.
Affected Systems
The Admin and Site Enhancements (ASE) WordPress plugin, versions prior to 9.0.1, is affected. Users of any of these releases who have been granted upload access in the plugin settings are vulnerable; no version information beyond "< 9.0.1" is provided. .
Risk and Exploitability
Given the moderate CVSS score and very low EPSS, the immediate risk is mild but the attack is feasible for attackers who can compromise a user with upload rights or insert malicious content into a site that hosts the OTA command. The vulnerability is not currently listed in the CISA KEV catalog, indicating no large‑scale exploitation has been recorded.
OpenCVE Enrichment