CVE-2026-19615

Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC

The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.


We have discovered 2,010 live websites that are affected by CVE-2026-19615.

Run a Free Instant Scan




Affected Software

Product  Admin Site Enhancements
Category Wordpress Plugins
Vulnerable Domains2,010 live websites (100% of Admin Site Enhancements install base)
Vulnerable Versions
  • from 0 through 9.0.1
Vulnerable Versions Count115 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 20, 2026
  • Updated - Aug 20, 2026

Credits

  • Mohammed Abd Alrahman (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-19615
United States498 websites



Germany242 websites
Romania220 websites
GB108 websites
Netherlands106 websites
Belgium72 websites
France60 websites
Canada50 websites
Italy48 websites
Spain45 websites

Website Distribution by TLD

Number of websites using CVE-2026-19615
.com710 websites
.de152 websites
.org100 websites
.nl95 websites
.co.uk76 websites
.be70 websites
.com.au37 websites
.net35 websites
.it31 websites
.com.br30 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-19615

Top websites that are affected by CVE-2026-19615. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States**,***
**********.com United States**,***
*********.ai United States**,***
*****.com United States***,***
***********.dk Denmark***,***
***.org United States***,***
******.ro Romania***,***
**************.us United States***,***
*********.org GB***,***
********.com United States***,***
See full domain list

FAQ

CVE-2026-19615 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Admin Site Enhancements
A total of 2,010 websites have been identified as vulnerable to CVE-2026-19615, based on global website indexing conducted by WebTechSurvey.
The Admin Site Enhancements is affected by the CVE-2026-19615 vulnerability.
Admin Site Enhancements versions up to 9.0.1 are vulnerable to CVE-2026-19615.
CVE-2026-19615 is resolved in version 9.0.1 of Admin Site Enhancements.