Description
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
Published: 2026-07-02
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ASE Pro plugin contains an unauthenticated cross‑site scripting flaw that allows arbitrary JavaScript to be injected into WordPress pages. Because authentication is not required, any user can trigger the injection by visiting the affected pages, and the injected code will execute in the browsers of anyone who views those pages. This weakness is classified under CWE‑79.

Affected Systems

WordPress sites running ASE Admin and Site Enhancements Pro plugin version 8.8.5 or older are affected. The core WordPress version or other plugins do not mitigate the vulnerability; any site with the vulnerable plugin installed is at risk.

Risk and Exploitability

The vulnerability has a CVSS v3.1 score of 9.6, indicating critical severity. The EPSS score is below 1 %, suggesting that active exploitation is currently rare. It is not listed in the CISA KEV catalog, so no confirmed exploitation campaigns are known. The flaw is unauthenticated, meaning an attacker can exploit it from any remote host that can reach the site, resulting in a high risk for site visitors.

Generated by OpenCVE AI on July 21, 2026 at 11:44 UTC.

Remediation

Vendor Solution

Update the WordPress Admin and Site Enhancements (ASE) Pro Plugin to the latest available version (at least 8.8.6).


OpenCVE Recommended Actions

  • Upgrade the ASE Admin and Site Enhancements Pro plugin to version 8.8.6 or newer, which removes the XSS flaw.
  • If an upgrade cannot be performed immediately, deactivate or uninstall the ASE Admin and Site Enhancements Pro plugin to eliminate the vulnerable code path.
  • As an additional precaution, implement a content‑security‑policy to block inline scripts or configure a web‑application‑firewall to filter suspicious requests targeting the plugin’s endpoints.

Generated by OpenCVE AI on July 21, 2026 at 11:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
Title WordPress Admin and Site Enhancements (ASE) Pro plugin <= 8.8.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T19:44:52.133Z

Reserved: 2026-06-25T08:03:02.838Z

Link: CVE-2026-57625

cve-icon Vulnrichment

Updated: 2026-07-02T19:44:46.874Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')