plugin

Advanced Access Manager Vulnerabilities

28 known security issues reported for the Advanced Access Manager WordPress plugin. Most recent disclosed May 14, 2026.

1 critical 3 high 8 medium

Running Advanced Access Manager on your site? Check whether your installed version is affected.

Scan your site free

Advanced Access Manager – Access Governance for WordPress <= 7.1.0 - Missing Authorization

medium

The Advanced Access Manager – Access Governance for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 7.1.0
Fixed in:
7.1.1
Disclosed:
May 14, 2026

CVE-2026-42674 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 5.9.9

unknown

[en] The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-confi...

Affected:
up to 5.9.9
Fixed in:
5.9.9
Disclosed:
Oct 16, 2024

CVE-2019-25213 on NVD →

Advanced Access Manager <= 6.9.20 - Reflected Cross-Site Scripting

medium

The Advanced Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.9.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can suc...

CVSS:
6.1
Affected:
up to 6.9.20
Fixed in:
6.9.21
Disclosed:
Mar 20, 2024

CVE-2024-29127 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 6.9.21

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Stored XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20.

Affected:
up to 6.9.21
Fixed in:
6.9.21
Disclosed:
Mar 19, 2024

CVE-2024-29124 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 6.9.21

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Reflected XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20.

Affected:
up to 6.9.21
Fixed in:
6.9.21
Disclosed:
Mar 19, 2024

CVE-2024-29127 on NVD →

Advanced Access Manager <= 6.9.20 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticat...

CVSS:
5.5
Affected:
up to 6.9.20
Fixed in:
6.9.21
Disclosed:
Mar 16, 2024

CVE-2024-29124 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 6.9.19

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and M...

Affected:
up to 6.9.19
Fixed in:
6.9.19
Disclosed:
Feb 1, 2024

CVE-2023-51674 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 6.9.16

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and M...

Affected:
up to 6.9.16
Fixed in:
6.9.16
Disclosed:
Dec 29, 2023

CVE-2023-50881 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 6.9.19

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.18.

Affected:
up to 6.9.19
Fixed in:
6.9.19
Disclosed:
Dec 29, 2023

CVE-2023-51675 on NVD →

Advanced Access Manager <= 6.9.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Advanced Access Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...

CVSS:
6.4
Affected:
up to 6.9.18
Fixed in:
6.9.19
Disclosed:
Dec 27, 2023

CVE-2023-51674 on NVD →

Advanced Access Manager <= 6.9.18 - Authenticated (Author+) Open Redirect

medium

The Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.9.18. This is due to insufficient validation on the redirect url supplied via params->redirect parameter. This makes it possible for aut...

CVSS:
4.3
Affected:
up to 6.9.18
Fixed in:
6.9.19
Disclosed:
Dec 27, 2023

CVE-2023-51675 on NVD →

Advanced Access Manager <= 6.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Advanced Access Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to, and including, 6.9.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to...

CVSS:
6.4
Affected:
up to 6.9.15
Fixed in:
6.9.16
Disclosed:
Dec 26, 2023

CVE-2023-50881 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 6.8.0

unknown

[en] The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 6.8.0
Fixed in:
6.8.0
Disclosed:
Nov 23, 2021

CVE-2021-24830 on NVD →

Advanced Access Manager <= 6.7.9 - Admin+ Stored Cross-Site Scripting

medium

The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS:
4.8
Affected:
up to 6.8.0
Fixed in:
6.8.0
Disclosed:
Oct 19, 2021

CVE-2021-24830 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 6.6.2

unknown

[en] The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metad...

Affected:
up to 6.6.2
Fixed in:
6.6.2
Disclosed:
Jan 1, 2021

CVE-2020-35934 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 6.6.2

unknown

[en] The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.)

Affected:
up to 6.6.2
Fixed in:
6.6.2
Disclosed:
Jan 1, 2021

CVE-2020-35935 on NVD →

Advanced Access Manager <= 6.6.1 - Authenticated Information Disclosure

medium

The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata a...

CVSS:
4.3
Affected:
up to 6.6.1
Fixed in:
6.6.2
Disclosed:
Aug 20, 2020

CVE-2020-35934 on NVD →

Advanced Access Manager <= 6.6.1 - Authenticated Authorization Bypass and Privilege Escalation

high

The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.)

CVSS:
7.5
Affected:
up to 6.6.1
Fixed in:
6.6.2
Disclosed:
Aug 14, 2020

CVE-2020-35935 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 2.8.3

unknown

[en] WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
Jan 13, 2020

CVE-2014-6059 on NVD →

Advanced Access Manager <= 5.9.8.1 - Unauthenticated Arbitrary File Read

critical

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

CVSS:
9.8
Affected:
up to 5.9.9
Fixed in:
5.9.9
Disclosed:
Sep 9, 2019

CVE-2019-25213 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 5.9.9

unknown

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

Affected:
up to 5.9.9
Fixed in:
5.9.9
Disclosed:
Sep 9, 2019

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 5.9.9

unknown

Arbitrary File Access/Download vulnerability found by "Props to Ov3rfly" in WordPress Advanced Access Manager plugin (versions <= 5.9.8.1).

Affected:
up to 5.9.9
Fixed in:
5.9.9
Disclosed:
Sep 9, 2019

Advanced Access Manager <= 3.2.1 - Unrestricted AJAX Actions allowing Privilege Escalation

high

The Advanced Access Manager plugin for WordPress does not use capability checks on any of its registered AJAX actions. This allows authenticated attackers with any privilege level, including subscribers, to perform actions including elevating their privileges to those of an administrator.

CVSS:
8.8
Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Jun 21, 2016

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 3.2.2

unknown

The Advanced Access Manager plugin for WordPress does not use capability checks on any of its registered AJAX actions. This allows authenticated attackers with any privilege level, including subscribers, to perform actions including elevating their privileges to those of an administrator.

Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Jun 21, 2016

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 3.2.2

unknown

Because of this vulnerability, users can change their privilege level. Update the plugin.

Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Jun 21, 2016

Advanced Access Manager <= 2.8.2 - Arbitrary File Overwrite

high

WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability

CVSS:
7.2
Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
Aug 20, 2014

CVE-2014-6059 on NVD →

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 3.2.2

unknown

Advanced Access Manager does not properly check if a user is authorized to execute AJAX actions, which allows a user to change their privilege level.

Affected:
up to 3.2.2
Fixed in:
3.2.2

Advanced Access Manager &#8211; Restricted Content, Users &amp; Roles, Enhanced Security and More [advanced-access-manager] < 5.9.9

unknown

The Advanced Access Manager WordPress plugin, versions before 5.9.9, allowed reading arbitrary files. This way one can download the wp-config.php file and get access to the database, which is publicly reachable on many servers. The affected function was the printMedia() function in the application/Core/Media.php fil...

Affected:
up to 5.9.9
Fixed in:
5.9.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database