Impact
CVE-2026-32423 describes a Missing Authorization flaw in the Bowo Admin and Site Enhancements (ASE) plugin (admin-site-enhancements). The vulnerability allows attackers to exploit incorrectly configured access control security levels, potentially granting unintended privileges through the plugin’s admin interface. This flaw is catalogued as CWE-862 and carries a CVSS score of 5.4, indicating moderate severity with risks primarily to data confidentiality and integrity rather than remote code execution.
Affected Systems
The issue affects the Bowo Admin and Site Enhancements (ASE) plugin on all WordPress deployments that have a plugin version n/a through <= 8.4.0. No lower bound is specified, so any release of the plugin with a version number not greater than 8.4.0 is considered vulnerable.
Risk and Exploitability
The EPSS score is reported as < 1 %, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is interaction with the plugin’s administrative endpoints; the flaw originates from insufficient authorization checks, so any authenticated user with access to the WordPress admin area could attempt to exploit the missing controls.
OpenCVE Enrichment