Impact
The ASE Pro plugin contains an unauthenticated cross‑site scripting flaw that allows arbitrary JavaScript to be injected into WordPress pages. Because authentication is not required, any user can trigger the injection by visiting the affected pages, and the injected code will execute in the browsers of anyone who views those pages. This weakness is classified under CWE‑79.
Affected Systems
WordPress sites running ASE Admin and Site Enhancements Pro plugin version 8.8.5 or older are affected. The core WordPress version or other plugins do not mitigate the vulnerability; any site with the vulnerable plugin installed is at risk.
Risk and Exploitability
The vulnerability has a CVSS v3.1 score of 9.6, indicating critical severity. The EPSS score is below 1 %, suggesting that active exploitation is currently rare. It is not listed in the CISA KEV catalog, so no confirmed exploitation campaigns are known. The flaw is unauthenticated, meaning an attacker can exploit it from any remote host that can reach the site, resulting in a high risk for site visitors.
OpenCVE Enrichment