CyberRota Analysis
AI-GeneratedThe Admin and Site Enhancements plugin for WordPress prior to version 9.0.1 is vulnerable due to inadequate sanitization of uploaded SVG files, enabling authenticated users with upload permissions to inject malicious JavaScript. This flaw could lead to cross-site scripting (XSS) attacks, compromising the security of users who access the affected files. WordPress site administrators and developers using this plugin should prioritize updating to version 9.0.1 or later to mitigate the risk.
Original NVD Description
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.