CVE Database /
CVE-2024-43333
CVE · High
CVE-2024-43333 — Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 7.6.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-43333
|
Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 7.6.3 |
Incorrect Privilege Assignment |
High
7.5
|
< 7.6.3
|
7.6.3 |
2025-02-03 |
—
|
CVE-2024-43333
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 7.6.2.1. This is due to the plugin not properly restricting user's ability to utilize the “View Admin as Role” feature. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recover access to a previous role, such as administrator, granted they had previously held a higher role. CVE-2025-24648 is a duplicate assignment of the same vulnerability.
Source:
Wordfence
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings