CyberRota Analysis
AI-GeneratedThe Admin and Site Enhancements (ASE) WordPress plugin prior to version 8.8.4 is vulnerable to unauthorized role restoration, allowing unauthenticated attackers to elevate a previously demoted administrator account back to its original privileges. This flaw poses a significant security risk as it can lead to unauthorized access and control over the WordPress site. WordPress administrators and security teams should prioritize patching to mitigate potential exploitation of this vulnerability.
Original NVD Description
The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API exposes.