CVE-2026-57625: WordPress Admin and Site Enhancements (ASE) Pro plugin <= 8.8.5 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Admin and Site Enhancements (ASE) Proto a version that resolves this vulnerability.Fixed in 8.8.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57625?
CVE-2026-57625 has a critical severity rating of 9.6.
What is the nature of the vulnerability in CVE-2026-57625?
CVE-2026-57625 is an unauthenticated Cross Site Scripting (XSS) vulnerability in the WordPress Admin and Site Enhancements (ASE) Pro plugin.
How do I fix CVE-2026-57625?
To fix CVE-2026-57625, you should update the WordPress Admin and Site Enhancements (ASE) Pro plugin to version 8.8.6 or later.
Which versions are affected by CVE-2026-57625?
CVE-2026-57625 affects versions of the WordPress Admin and Site Enhancements (ASE) Pro plugin up to and including 8.8.5.
What can an attacker do with CVE-2026-57625?
An attacker exploiting CVE-2026-57625 can execute arbitrary scripts in the context of the user’s session on the affected site.