CVE · Critical

CVE-2026-16610 — Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16610 Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.9.1 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 8.9.1 8.9.1 2026-06-29

CVE-2026-16610

The Admin and Site Enhancements Pro plugin for WordPress contains a security flaw in versions up to 8.9.0 that allows an attacker without authentication to inject malicious code on the server. This vulnerability arises from a combination of factors, including the frontend save handler's reliance on a publicly available nonce with no verification check, the bypassability of CAPTCHA validation by omitting a required key, and the storage of unsanitized repeater row keys in eval() calls within the recursive_html function.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.