CVE-2026-19615 PUBLISHED

Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC

Assigner: WPScan
Reserved: 12.08.2026 Published: 20.08.2026 Updated: 20.08.2026

The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.

Product Status

Vendor Unknown
Product Admin and Site Enhancements (ASE)
Versions Default: unaffected
  • affected from 0 to 9.0.1 (excl.)

Credits

  • Mohammed Abd Alrahman finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE