PLUGIN SECURITY
Is Admin and Site Enhancements (ASE) Pro safe?
Duplicate post, post order, image resize, email via SMTP, admin menu editor, custom css / code, disable gutenberg and much more in a single plugin.
What this plugin does
- Slug:
admin-site-enhancements-pro - Author: Bowo
- 200000+ active installs
- 100/100 rating (421 reviews on wordpress.org)
- 10873849 all-time downloads
- On WordPress.org since 2022-10-26
enhancementsoptimizationstoolstweaks
Maintenance status
- Latest known version: 8.9.2
- Last updated: 2026-08-30 11:59pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 5.6+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
5 known CVEs on file for Admin and Site Enhancements (ASE) Pro. Reported between 2025 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-57625 | Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.8.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Critical 9.6 | < 8.8.6 | 8.8.6 | 2026-06-29 | ✓ fixed in latest |
| CVE-2026-16610 | Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.9.1 | Unrestricted Upload of File with Dangerous Type | Critical 9.8 | < 8.9.1 | 8.9.1 | 2026-06-29 | ✓ fixed in latest |
| CVE-2026-12083 | Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 8.8.4 | Improper Privilege Management | Unknown | < 8.8.4 | 8.8.4 | 2026-06-26 | ✓ fixed in latest |
| CVE-2024-43333 | Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 7.6.3 | Incorrect Privilege Assignment | High 7.5 | < 7.6.3 | 7.6.3 | 2025-02-03 | ✓ fixed in latest |
| CVE-2025-24653 | Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] < 7.6.3 | Missing Authorization | Medium 4.3 | < 7.6.3 | 7.6.3 | 2025-01-24 | ✓ fixed in latest |
How to fix it
Keep Admin and Site Enhancements (ASE) Pro updated — 8.9.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WP EXtra – One Click Optimize — 6000+ active installs — 98/100 (41) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.