Resources /
WordPress Plugins /
Admin and Site Enhancements (ASE) Pro
PLUGIN SECURITY
Is Admin and Site Enhancements (ASE) Pro safe?
Duplicate post, post order, image resize, email via SMTP, admin menu editor, custom css / code, disable gutenberg and much more in a single plugin.
What this plugin does
- Slug:
admin-site-enhancements-pro
- Author: Bowo
- 200000+ active installs
- 100/100 rating (418 reviews on wordpress.org)
- 10200991 all-time downloads
- On WordPress.org since 2022-10-26
enhancementsoptimizationstoolstweaks
Maintenance status
- Last updated: 2026-07-19 11:55pm GMT
- Tested up to WordPress: 7.0.2
- Requires PHP: 5.6+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
4 known CVEs on file for Admin and Site Enhancements (ASE) Pro.
Reported between 2025 and 2026.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12083
|
Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.8.4 |
Improper Privilege Management |
Unknown
|
< 8.8.4
|
8.8.4 |
2026-07-06 |
—
|
|
CVE-2026-57625
|
Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.8.6 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Critical
9.6
|
< 8.8.6
|
8.8.6 |
2026-06-29 |
—
|
|
CVE-2024-43333
|
Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 7.6.3 |
Incorrect Privilege Assignment |
High
7.5
|
< 7.6.3
|
7.6.3 |
2025-02-03 |
—
|
|
CVE-2025-24653
|
Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 7.6.3 |
Missing Authorization |
Medium
4.3
|
< 7.6.3
|
7.6.3 |
2025-01-24 |
—
|
CVE-2026-12083
The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API exposes.
Source:
CVE.org
CVE-2026-57625
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
Wordfence
CVE-2024-43333
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 7.6.2.1. This is due to the plugin not properly restricting user's ability to utilize the “View Admin as Role” feature. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recover access to a previous role, such as administrator, granted they had previously held a higher role. CVE-2025-24648 is a duplicate assignment of the same vulnerability.
Source:
Wordfence
CVE-2025-24653
The admin-site-enhancements-pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.6.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Source:
Wordfence
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.