A critical security flaw has been identified in the ASE Pro (Admin and Site Enhancements) plugin for WordPress, affecting all versions up to and including 8.9.0. This vulnerability lets unauthenticated third parties run arbitrary code directly on your website's server, which can give attackers full control of your site, access to sensitive visitor or business data, or let them use your server for malicious purposes. The flaw can only be exploited if your site has the [post_cf_form] shortcode active on at least one publicly accessible page, a common setup for sites using this plugin's form features. The plugin's built-in security checks for this functionality are insufficient, so attackers do not need a WordPress account, admin login, or any prior access to your site to carry out an attack.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16610