cleantalk
Vulnerabilities and Security Researches

Admin and Site Enhancements (ASE), CVE-2024-13685

CVE, Research URL

CVE-2024-13685

Published on
Mar 04, 2025
Research Description
The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value to bypass the login limit feature in the Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10.
Affected versions
Min -, max 7.6.10.
Status
vulnerable