Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30407 | The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc.php when such uploads are enabled, which could allow users to upload a malicious SVG containing XSS payloads |
Tue, 23 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpase Wpase admin And Site Enhancements |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpase Wpase admin And Site Enhancements |
Mon, 22 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 22 Sep 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc.php when such uploads are enabled, which could allow users to upload a malicious SVG containing XSS payloads | |
| Title | Admin and Site Enhancements < 7.9.8 - Authenticated Stored XSS via SVG | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-09-22T16:10:43.154Z
Reserved: 2025-08-26T12:17:12.507Z
Link: CVE-2025-9487
Updated: 2025-09-22T16:10:29.113Z
Status : Deferred
Published: 2025-09-22T06:15:35.487
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-9487
No data.
OpenCVE Enrichment
Updated: 2025-09-23T16:10:04Z
No weakness.
EUVD