Access violation vulnerability in Admin and Site Enhancements (ASE) 7.6.2.1

A popular plugin for WordPress called “Admin and Site Enhancements (ASE) Pro” has a security issue that affects all versions up to 7.6.2.1. The problem is that the plugin doesn’t control users’ ability to use the “View Admin as Role” feature. This means that if an attacker has at least Subscriber-level access, they can regain access to a higher role (like administrator) that they used to have. The vulnerability has been assigned the code CVE-2025-24648.

Detected in:

Admin and Site Enhancements (ASE) fixed vulnerable versions: >= * <= 7.6.2.1
Admin and Site Enhancements (ASE) Pro fixed vulnerable versions: >= * <= 7.6.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.