Admin and Site Enhancements (ASE) <= 9.1.4 - Unauthenticated Denial of Service via 'asenha_password_protection' Cookie

Medium 5.9 CWE-405Fixed in 9.2.0
ID
WPSEC-2026-0450
Plugin
Admin and Site Enhancements (ASE) (admin-site-enhancements)
Affected
from 5.8.0 before 9.2.0
Remediation
Update to 9.2.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness
CWE-405
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
Admin and Site Enhancements (ASE) on WPSec AttackSurface
Fix released
Published

Description

The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Denial of Service via the 'asenha_password_protection' cookie in versions 5.8.0 up to, and including, 9.1.4. This is due to the Password Protection module passing the raw, visitor-supplied cookie value to wp_check_password() as the stored hash, which lets the visitor choose the hashing algorithm and its cost factor. This makes it possible for unauthenticated attackers to send a bcrypt string with a very high cost factor in the cookie, so that each request keeps a PHP worker busy until the PHP execution time limit ends it, and a small number of requests can make the site unavailable. Exploitation requires the Password Protection module, which is off by default, to be enabled.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0