CVE-2026-32423: WordPress Admin and Site Enhancements (ASE) plugin <= 8.4.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 8.4.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32423?
CVE-2026-32423 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to administrative functionalities.
How do I fix CVE-2026-32423?
To fix CVE-2026-32423, update the WordPress Admin and Site Enhancements (ASE) plugin to version 8.4.1 or later.
What types of software are affected by CVE-2026-32423?
CVE-2026-32423 affects the WordPress Admin and Site Enhancements (ASE) plugin version 8.4.0 and earlier.
What kind of access does CVE-2026-32423 compromise?
CVE-2026-32423 compromises security by allowing incorrect configuration of access control levels for administrative functionalities.
Is there a known exploit for CVE-2026-32423?
Yes, CVE-2026-32423 can be exploited by attackers due to missing authorization checks in the administrative area.