Admin and Site Enhancements (ASE) <= 5.7.1 - Password Protection Mode Security Feature Bypass

2023-10-25 00:00
Abu Hurayra (HurayraIIT)

Strategic Overview

Status
Patched in 5.8.0
Affected Version<= 5.7.1
CVSS7.5High
CVECVE-2023-46630
View all Admin and Site Enhancements (ASE) vulnerabilities

Vulnerability Overview

The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to security feature bypass in all versions up to, and including, 5.7.1. This is due to a flawed authentication mechanism within the maybe_process_login function. This makes it possible for unauthenticated attackers to bypass the Password Protection feature and view password protected pages.

Technical Analysis

REMEDIATION: Update to version 5.8.0, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C