CVE-2025-24649

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 862

Summary

CVE-2025-24649 is a missing authorization vulnerability affecting the Admin and Site Enhancements (ASE) plugin for wpase.com. This issue enables unauthorized access to features and functionalities, putting incorrectly configured access control security levels at risk. The vulnerability, which affects versions 7.6.2 and below, allows exploitation of this flaw, potentially leading to serious security consequences for websites utilizing the ASE plugin. Users are advised to upgrade to the latest version or consider disabling the plugin until a patch is available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share