Lucene search

K
wpvulndbWpvulndbWPVDB-ID:6CE7D3B8-47F8-4C52-AEB5-57873FEB0DE9
HistoryNov 23, 2023 - 12:00 a.m.

Admin and Site Enhancements (ASE) < 5.8.0 - Password Protection Mode Security Feature Bypass

2023-11-2300:00:00
wpscan.com
15
wordpress
ase plugin
security bypass
authentication mechanism
unauthenticated attackers
password protection

AI Score

7.5

Confidence

Low

EPSS

0

Percentile

9.0%

Description The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to security feature bypass in all versions up to, and including, 5.7.1. This is due to a flawed authentication mechanism within the maybe_process_login function. This makes it possible for unauthenticated attackers to bypass the Password Protection feature and view password protected pages.

AI Score

7.5

Confidence

Low

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:6CE7D3B8-47F8-4C52-AEB5-57873FEB0DE9