What is CVE-2026-16610?
CVE-2026-16610 is a Remote Code Execution vulnerability in the Admin and Site Enhancements (ASE) Pro plugin for WordPress, affecting versions up to and including 8.9.0 via the `recursive_html` function. It occurs because the frontend save handler enforces only a publicly emitted nonce without authentication or CAPTCHA validation. Users should update to the latest patched version immediately.
Azərbaycanca: CVE-2026-16610, WordPress üçün Admin and Site Enhancements (ASE) Pro plugin-inin 8.9.0 və daha əvvəlki versiyalarında `recursive_html` funksiyası vasitəsilə uzaqdan kod icrası (Remote Code Execution) zəifliyidir. Bu, frontend save handler-də yalnız ictimai nonce istifadə edilməsi və autentifikasiya yoxlanışının olmaması səbəbindən baş verir. İstifadəçilər plugin-i dərhal ən son versiyaya yeniləməlidir.
FAQ2
Through which component of the ASE Pro plugin is CVE-2026-16610 exploited?
The vulnerability is exploited through the plugin's `recursive_html` function.
What is the root cause of CVE-2026-16610?
The root cause of this RCE vulnerability is that the frontend save handler only uses a publicly emitted nonce without authentication verification.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.