CVE-2024-43333
Published: 03 February 2025
Description
Incorrect Privilege Assignment vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.2.1.
Security Summary
CVE-2024-43333 is an Incorrect Privilege Assignment vulnerability (CWE-266) in the NotFound Admin and Site Enhancements (ASE) Pro WordPress plugin, enabling privilege escalation. The issue affects all versions of the plugin from its initial release through 7.6.2.1. It has a CVSS v3.1 base score of 7.5 (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating network accessibility but high attack complexity.
A low-privileged authenticated user can exploit this vulnerability remotely without user interaction. Successful exploitation allows the attacker to escalate privileges, potentially gaining unauthorized high-level access such as administrator rights on the affected WordPress site, with high impacts on confidentiality, integrity, and availability.
The Patchstack advisory at https://patchstack.com/database/wordpress/plugin/admin-site-enhancements-pro/vulnerability/wordpress-admin-and-site-enhancements-ase-pro-plugin-7-6-2-1-privilege-escalation-vulnerability?_s_id=cve documents this privilege escalation vulnerability in ASE Pro versions through 7.6.2.1, recommending updates to mitigate the risk.
Details
- CWE(s)