Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-57625: WordPress ASE Pro <= 8.8.5 Cross Site Scripting Risk
CVE-2026-57625
CVE-2026-57625
Summary
An attacker can inject malicious code into WordPress sites using the ASE Pro plugin, potentially allowing them to steal sensitive information or take control of the site. This vulnerability affects all versions of the ASE Pro plugin up to 8.8.5. Update the plugin to the latest version to fix this issue.
What to do
- Update ase admin and site enhancements (ase) pro to version 8.8.6.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ase | admin and site enhancements (ase) pro |
<= 8.8.5 Fix: upgrade to 8.8.6
|
Original title
WordPress Admin and Site Enhancements (ASE) Pro plugin <= 8.8.5 - Cross Site Scripting (XSS) vulnerability
Original description
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
nvd CVSS3.1
9.6
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 2 Jul 2026 · Updated: 20 Jul 2026 · First seen: 2 Jul 2026