Admin and Site Enhancements (ASE) <= 7.6.9 - Password Protection Bypass
2025-04-07 00:00
Dogus DemirkiranStrategic Overview
StatusPatched in 7.6.10
Affected PluginAdmin and Site Enhancements (ASE)
Affected Version
<= 7.6.9CVSS5.3Medium
CVE
CVE-2024-13688Vulnerability Overview
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Password Protection Bypass in all versions up to, and including, 7.6.9. This is due to the plugin using a hardcoded password for password protection. This makes it possible for unauthenticated attackers to access a password protected site.
Technical Analysis
REMEDIATION: Update to version 7.6.10, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C