CVE-2025-24653: WordPress Admin and Site Enhancements (ASE) Pro Plugin <= 7.6.1.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in NotFound Admin and Site Enhancements (ASE) Pro admin-site-enhancements-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through <= 7.6.1.1.
Other sources
Missing Authorization vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.1.1.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24653?
CVE-2025-24653 is classified as a critical vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-24653?
To fix CVE-2025-24653, update your NotFound Admin and Site Enhancements (ASE) Pro to the latest version beyond 7.6.1.1.
What systems are affected by CVE-2025-24653?
CVE-2025-24653 affects NotFound Admin and Site Enhancements (ASE) Pro versions up to 7.6.1.1 and the WordPress Admin and Site Enhancements (ASE) Pro Plugin.
What kind of attack can exploit CVE-2025-24653?
CVE-2025-24653 can be exploited to gain unauthorized access, potentially allowing attackers to manipulate site settings or access sensitive information.
Is there a workaround for CVE-2025-24653?
There is no official workaround for CVE-2025-24653; upgrading to a patched version is the recommended solution.