SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19615

MEDIUM · CVSS 6.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Admin and Site Enhancements plugin for WordPress prior to version 9.0.1 is vulnerable due to inadequate sanitization of uploaded SVG files, enabling authenticated users with upload permissions to inject malicious JavaScript. This flaw could lead to cross-site scripting (XSS) attacks, compromising the security of users who access the affected files. WordPress site administrators and developers using this plugin should prioritize updating to version 9.0.1 or later to mitigate the risk.

CVE
CVE-2026-19615
Severity
MEDIUM
CVSS
6.8
EPSS
0.29%
WordPress Java

Original NVD Description

The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.