Admin Management Xtended [admin-management-xtended] <= 2.5.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in wpseek Admin Management Xtended admin-management-xtended allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin Management Xtended : from n/a through <= 2.5.1.
- Affected:
- up to 2.5.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 27, 2025
CVE-2025-62965 on NVD →
Admin Management Xtended <= 2.5.1 - Missing Authorization
medium
The Admin Management Xtended plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.2
- Disclosed:
- Oct 17, 2025
CVE-2025-62965 on NVD →
Admin Management Xtended [admin-management-xtended] < 2.4.7
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oliver Schlöbe Admin Management Xtended allows Stored XSS.This issue affects Admin Management Xtended: from n/a through 2.4.6.
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- Oct 17, 2024
CVE-2024-49307 on NVD →
Admin Management Xtended <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Admin Management Xtended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Oct 15, 2024
CVE-2024-49307 on NVD →
Admin Management Xtended [admin-management-xtended] < 2.4.5
unknown
[en] The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and m...
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.5
- Disclosed:
- Jul 11, 2022
CVE-2022-1599 on NVD →
Admin Management Xtended <= 2.4.4 - Cross-Site Request Forgery to Post Status Update
medium
The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.
- CVSS:
- 4.3
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.5
- Disclosed:
- Jun 20, 2022
CVE-2022-1599 on NVD →
Admin Management Xtended [admin-management-xtended] < 2.4.5
unknown
[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.5
- Disclosed:
- Jun 15, 2022
CVE-2022-29450 on NVD →
Admin Management Xtended <= 2.4.4 - Cross-Site Request Forgery
high
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.
- CVSS:
- 8.8
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.5
- Disclosed:
- May 27, 2022
CVE-2022-29450 on NVD →
Admin Management Xtended [admin-management-xtended] < 2.4.0.1
unknown
[en] The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.
- Affected:
- up to 2.4.0.1
- Fixed in:
- 2.4.0.1
- Disclosed:
- Sep 20, 2019
CVE-2015-9390 on NVD →
Admin Management Xtended <= 2.4.0 - Missing Authorization Checks
medium
The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.
- CVSS:
- 4.3
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.0.1
- Disclosed:
- Dec 14, 2015
CVE-2015-9390 on NVD →
Admin Management Xtended [admin-management-xtended] < 2.4.1
unknown
Because of this vulnerability, there is no privilege check inside almost all "wp_ajax" functions.
Update the plugin.
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Dec 14, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database