Vulnerability Description
The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection offered via a crafted request
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpase | Admin And Site Enhancements | < 7.6.10 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/19051d08-16b0-466c-976b-be7b076e8e92/ExploitThird Party Advisory
FAQ
What is CVE-2024-13688?
CVE-2024-13688 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection offered via a crafted requ...
How severe is CVE-2024-13688?
CVE-2024-13688 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-13688?
Check the references section above for vendor advisories and patch information. Affected products include: Wpase Admin And Site Enhancements.