{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/admin-and-site-enhancements-ase-pro--8.9.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-16610"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Admin and Site Enhancements (ASE) Pro (\u003c= 8.9.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Admin and Site Enhancements (ASE) Pro plugin for WordPress, in all versions up to and including 8.9.0, contains a critical vulnerability enabling unauthenticated Remote Code Execution (RCE). The flaw exists within the recursive_html function, which processes user-provided input without adequate sanitization or authentication validation. An attacker can bypass both nonce verification and CAPTCHA mechanisms to submit malicious payloads via the cfgroup[input] parameter. This payload is subsequently passed into an eval() function call. Successful exploitation is contingent on the [post_cf_form] shortcode being present on a publicly accessible page, which allows the attacker to harvest the necessary session identifiers and nonces required to interact with the vulnerable save handler. This vulnerability represents a significant risk to WordPress site integrity as it provides an unauthenticated path for arbitrary command execution on the underlying server.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker browses a public-facing WordPress page to identify the presence of the [post_cf_form] shortcode.\u003c/li\u003e\n\u003cli\u003eAttacker loads the target page to retrieve the session ID and nonce emitted by the plugin to the frontend.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious request targeting the plugin's frontend save handler.\u003c/li\u003e\n\u003cli\u003eAttacker omits the CAPTCHA key and includes a crafted payload within the cfgroup[input] parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin server receives the request, failing to validate the provided nonce and CAPTCHA.\u003c/li\u003e\n\u003cli\u003eThe backend recursive_html function processes the malicious cfgroup[input] content.\u003c/li\u003e\n\u003cli\u003eThe application executes the unsanitized input via an eval() call.\u003c/li\u003e\n\u003cli\u003eArbitrary code executes on the host, granting the attacker server-level access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated attackers to gain remote code execution capabilities on the hosting server. This can lead to full site compromise, sensitive data exfiltration, and the installation of persistent backdoors. Given the ubiquity of WordPress plugins, all sites utilizing ASE Pro version 8.9.0 or earlier are at immediate risk of exploitation if the [post_cf_form] shortcode is exposed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate the ASE Pro plugin to the latest version immediately to remediate CVE-2026-16610.\u003c/li\u003e\n\u003cli\u003eAudit all public-facing pages for the presence of the [post_cf_form] shortcode and remove it if it is not strictly required.\u003c/li\u003e\n\u003cli\u003eDeploy the provided web server detection rules to monitor for suspicious POST requests containing common PHP command execution patterns.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests directed to the plugin's save handler endpoint that lack legitimate CAPTCHA or nonce headers.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T07:19:30Z","date_published":"2026-07-30T07:19:30Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ase-pro-rce/","summary":"The ASE Pro WordPress plugin up to version 8.9.0 is vulnerable to unauthenticated remote code execution via insecure input handling in the recursive_html function.","title":"Unauthenticated Remote Code Execution in ASE Pro WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-07-ase-pro-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Admin and Site Enhancements (ASE) Pro (\u003c= 8.9.0)","version":"https://jsonfeed.org/version/1.1"}