Admin and Site Enhancements (ASE) <= 7.6.9 - Password Protection Bypass

2025-04-07 00:00
Dogus Demirkiran

Strategic Overview

Status
Patched in 7.6.10
Affected Version<= 7.6.9
CVSS5.3Medium
CVECVE-2024-13688
View all Admin and Site Enhancements (ASE) vulnerabilities

Vulnerability Overview

The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Password Protection Bypass in all versions up to, and including, 7.6.9. This is due to the plugin using a hardcoded password for password protection. This makes it possible for unauthenticated attackers to access a password protected site.

Technical Analysis

REMEDIATION: Update to version 7.6.10, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C