plugin

Admin Management Xtended Vulnerabilities

11 known security issues reported for the Admin Management Xtended WordPress plugin. Most recent disclosed Oct 27, 2025.

1 high 4 medium

Running Admin Management Xtended on your site? Check whether your installed version is affected.

Scan your site free

Admin Management Xtended [admin-management-xtended] <= 2.5.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in wpseek Admin Management Xtended admin-management-xtended allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin Management Xtended : from n/a through <= 2.5.1.

Affected:
up to 2.5.1
Fix:
No patched version reported
Disclosed:
Oct 27, 2025

CVE-2025-62965 on NVD →

Admin Management Xtended <= 2.5.1 - Missing Authorization

medium

The Admin Management Xtended plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
Oct 17, 2025

CVE-2025-62965 on NVD →

Admin Management Xtended [admin-management-xtended] < 2.4.7

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oliver Schlöbe Admin Management Xtended allows Stored XSS.This issue affects Admin Management Xtended: from n/a through 2.4.6.

Affected:
up to 2.4.7
Fixed in:
2.4.7
Disclosed:
Oct 17, 2024

CVE-2024-49307 on NVD →

Admin Management Xtended <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Admin Management Xtended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Oct 15, 2024

CVE-2024-49307 on NVD →

Admin Management Xtended [admin-management-xtended] < 2.4.5

unknown

[en] The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and m...

Affected:
up to 2.4.5
Fixed in:
2.4.5
Disclosed:
Jul 11, 2022

CVE-2022-1599 on NVD →

Admin Management Xtended <= 2.4.4 - Cross-Site Request Forgery to Post Status Update

medium

The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.

CVSS:
4.3
Affected:
up to 2.4.5
Fixed in:
2.4.5
Disclosed:
Jun 20, 2022

CVE-2022-1599 on NVD →

Admin Management Xtended [admin-management-xtended] < 2.4.5

unknown

[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.

Affected:
up to 2.4.5
Fixed in:
2.4.5
Disclosed:
Jun 15, 2022

CVE-2022-29450 on NVD →

Admin Management Xtended <= 2.4.4 - Cross-Site Request Forgery

high

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.

CVSS:
8.8
Affected:
up to 2.4.4
Fixed in:
2.4.5
Disclosed:
May 27, 2022

CVE-2022-29450 on NVD →

Admin Management Xtended [admin-management-xtended] < 2.4.0.1

unknown

[en] The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.

Affected:
up to 2.4.0.1
Fixed in:
2.4.0.1
Disclosed:
Sep 20, 2019

CVE-2015-9390 on NVD →

Admin Management Xtended <= 2.4.0 - Missing Authorization Checks

medium

The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.

CVSS:
4.3
Affected:
up to 2.4.0
Fixed in:
2.4.0.1
Disclosed:
Dec 14, 2015

CVE-2015-9390 on NVD →

Admin Management Xtended [admin-management-xtended] < 2.4.1

unknown

Because of this vulnerability, there is no privilege check inside almost all "wp_ajax" functions. Update the plugin.

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Dec 14, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database