WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Admin and Site Enhancements (ASE)

Duplicate post, post order, image resize, email via SMTP, admin menu editor, custom css / code, disable gutenberg and much more in a single plugin.

12Reported vulnerabilities
8.8Highest CVSS score
9.0.1Latest version
200,000+Active installs

What to do now

Update Admin and Site Enhancements (ASE) to 9.0.1 or later. 12 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-24648 High 8.8 0.4% 7.6.2.1 and earlier 7.6.3 January 20, 2026
CVE-2024-43333 High 7.5 0.4% 7.6.2.1 and earlier 7.6.3 February 3, 2025
CVE-2023-46630 High 7.5 0.4% 5.7.1 and earlier 5.8.0 October 25, 2023
CVE-2026-19615 Medium 6.4 0.3% Before 9.0.1 9.0.1 August 21, 2026
CVE-2024-10790 Medium 5.4 0.3% 0 to 7.5.1 (inclusive) 7.5.2 November 12, 2024
CVE-2026-12083 Medium 5.3 0.5% 8.8.3 and earlier 8.8.4 June 26, 2026
CVE-2025-9487 Medium 5.4 0.2% 7.9.7 and earlier 7.9.8 September 1, 2025
CVE-2024-13688 Medium 5.3 0.4% 7.6.9 and earlier 7.6.10 April 7, 2025
CVE-2024-13685 Medium 5.3 0.4% 7.6.9 and earlier 7.6.10 February 11, 2025
CVE-2026-32423 Medium 4.3 0.2% 8.4.0 and earlier 8.4.1 February 27, 2026
CVE-2025-64255 Medium 4.3 0.3% 8.0.8 and earlier 8.1.0 December 15, 2025
CVE-2025-24649 Low 3.1 0.4% 7.6.2 and earlier 7.6.3 January 24, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.