WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Admin and Site Enhancements (ASE) Pro safe?

Duplicate post, post order, image resize, email via SMTP, admin menu editor, custom css / code, disable gutenberg and much more in a single plugin.

What this plugin does

  • Slug: admin-site-enhancements-pro
  • Author: Bowo
  • 200000+ active installs
  • 100/100 rating (418 reviews on wordpress.org)
  • 10200991 all-time downloads
  • On WordPress.org since 2022-10-26

enhancementsoptimizationstoolstweaks

Maintenance status

  • Last updated: 2026-07-19 11:55pm GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 5.6+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

4 known CVEs on file for Admin and Site Enhancements (ASE) Pro. Reported between 2025 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12083 Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.8.4 Improper Privilege Management Unknown < 8.8.4 8.8.4 2026-07-06
CVE-2026-57625 Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.8.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Critical 9.6 < 8.8.6 8.8.6 2026-06-29
CVE-2024-43333 Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 7.6.3 Incorrect Privilege Assignment High 7.5 < 7.6.3 7.6.3 2025-02-03
CVE-2025-24653 Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 7.6.3 Missing Authorization Medium 4.3 < 7.6.3 7.6.3 2025-01-24

CVE-2026-12083

The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API exposes.

Source: CVE.org

CVE-2026-57625

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2024-43333

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 7.6.2.1. This is due to the plugin not properly restricting user's ability to utilize the “View Admin as Role” feature. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recover access to a previous role, such as administrator, granted they had previously held a higher role. CVE-2025-24648 is a duplicate assignment of the same vulnerability.

Source: Wordfence

CVE-2025-24653

The admin-site-enhancements-pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.6.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.