CVE-2024-13688
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 28, 2025
Updated: May 14, 2025
CWE ID 798
Summary
CVE-2024-13688 is a newly discovered vulnerability in the Admin and Site Enhancements (ASE) WordPress plugin. Affecting versions before 7.6.10, this issue arises due to a hardcoded password in the plugin's Password Protection feature. An attacker can exploit this vulnerability by crafting a specific request, effectively bypassing the password protection and gaining unauthorized access. It is essential for users to update the plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.