PT-2025-9633 · WordPress · Admin/Site Enhancements (Ase) Wordpress Plugin

Dogus Demirkiran

·

Published

2025-03-04

·

Updated

2025-03-05

·

CVE-2024-13685

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Admin and Site Enhancements (ASE) WordPress plugin versions prior to 7.6.10
Description The issue allows an attacker to manipulate client IP addresses retrieved from potentially untrusted headers, enabling them to bypass the login limit feature.
Recommendations For versions prior to 7.6.10, update to version 7.6.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the login feature to minimize the risk of exploitation.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13685

Affected Products

Admin/Site Enhancements (Ase) Wordpress Plugin