CVE Database /
CVE-2026-12083
CVE
CVE-2026-12083 — Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.8.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12083
|
Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.8.4 |
Improper Privilege Management |
Unknown
|
< 8.8.4
|
8.8.4 |
2026-06-26 |
—
|
CVE-2026-12083
The Admin and Site Enhancements plugin, versions prior to 8.8.4, contains a security flaw that enables unauthorized users to reinstate previously stripped administrative privileges without proper verification or validation checks in place. This vulnerability stems from an incomplete patch for earlier issues related to the WordPress role API's demotion functionality. As a result, malicious actors can exploit this weakness to regain administrator access.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings