Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19615— Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC

Quick assessment

Affected
Unknown Admin and Site Enhancements (ASE)
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 WordPress 插件 Admin and Site Enhancements (ASE) 9.0.1 之前的版本中,该插件并未对用户通过任何接受上传途径提交的 SVG 文件进行有效的过滤处理。这使得拥有站点所有者赋予的上传权限的用户能够上传包含 JavaScript 代码的文件。当任何人打开该文件时,其中的 JavaScript 代码将在其浏览器中执行,从而可能导致潜在的安全风险。

AI Predicted 7.5 Difficulty: Easy EPSS 0.29% · P21

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Admin and Site Enhancements (ASE) < 9.0.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19615

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC
Source: CVE Program / CVE List V5
Vulnerability Description
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Admin and Site Enhancements (ASE) 0 ~ 9.0.1 -

II. Public POCs for CVE-2026-19615

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19615

登录查看更多情报信息。

Vendor Advisories for CVE-2026-19615 (1)

Same Patch Batch · Unknown · 2026-08-20 · 7 CVEs total

CVE-2026-75860 JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update
CVE-2026-74992 Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload
CVE-2026-19699 GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure
CVE-2026-19697 GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload
CVE-2026-15049 Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import
CVE-2026-13405 Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder

IV. Related Vulnerabilities

V. Comments for CVE-2026-19615

No comments yet


Leave a comment