CVE-2024-43333
WordPress vulnerability analysis and mitigation

Overview

The Admin and Site Enhancements (ASE) Pro plugin, affecting over 100,000 WordPress installations, contains a privilege escalation vulnerability (CVE-2024-43333) discovered in versions through 7.6.2.1. The vulnerability was identified on December 13, 2024, and publicly disclosed on February 3, 2025. This security issue affects both the free and pro versions of the plugin (Patchstack Article).

Technical details

The vulnerability stems from broken logic in the 'View Admin as Role' feature, which allows users to recover their previous role. The issue is classified as an Incorrect Privilege Assignment (CWE-266) with a CVSS v3.1 score of 7.5 (High), using the vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. The vulnerability occurs when a user's role is downgraded; they can potentially recover their previous, higher-privileged role if the 'View Admin as Role' feature is enabled (Patchstack Article, NVD).

Impact

The vulnerability allows authenticated users to potentially escalate their privileges by recovering their previous role configurations. For example, if a user was previously an Administrator and was downgraded to a Subscriber, they could exploit this vulnerability to regain Administrator privileges, potentially leading to full website control (Patchstack Article).

Mitigation and workarounds

The vulnerability has been patched in version 7.6.3 of both the free and pro versions of the plugin. The fix includes adding a function hook to delete the asenhaviewadminasoriginalroles user meta when there is a profile update on the user. Users are strongly advised to update to version 7.6.3 or later (Patchstack Article).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management