AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-12083

HIGH · CVSS 8.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

The Admin and Site Enhancements (ASE) WordPress plugin prior to version 8.8.4 is vulnerable to unauthorized role restoration, allowing unauthenticated attackers to elevate a previously demoted administrator account back to its original privileges. This flaw poses a significant security risk as it can lead to unauthorized access and control over the WordPress site. WordPress administrators and security teams should prioritize patching to mitigate potential exploitation of this vulnerability.

CVE
CVE-2026-12083
Severity
HIGH
CVSS
8.1
EPSS
0.29%
WordPress

Original NVD Description

The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API exposes.