Advanced Access Manager – Access Governance for WordPress <= 7.1.0 - Missing Authorization
medium
The Advanced Access Manager – Access Governance for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 7.1.0
- Fixed in:
- 7.1.1
- Disclosed:
- May 14, 2026
CVE-2026-42674 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 5.9.9
unknown
[en] The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-confi...
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.9
- Disclosed:
- Oct 16, 2024
CVE-2019-25213 on NVD →
Advanced Access Manager <= 6.9.20 - Reflected Cross-Site Scripting
medium
The Advanced Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.9.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can suc...
- CVSS:
- 6.1
- Affected:
- up to 6.9.20
- Fixed in:
- 6.9.21
- Disclosed:
- Mar 20, 2024
CVE-2024-29127 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 6.9.21
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Stored XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20.
- Affected:
- up to 6.9.21
- Fixed in:
- 6.9.21
- Disclosed:
- Mar 19, 2024
CVE-2024-29124 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 6.9.21
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Reflected XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20.
- Affected:
- up to 6.9.21
- Fixed in:
- 6.9.21
- Disclosed:
- Mar 19, 2024
CVE-2024-29127 on NVD →
Advanced Access Manager <= 6.9.20 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticat...
- CVSS:
- 5.5
- Affected:
- up to 6.9.20
- Fixed in:
- 6.9.21
- Disclosed:
- Mar 16, 2024
CVE-2024-29124 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 6.9.19
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and M...
- Affected:
- up to 6.9.19
- Fixed in:
- 6.9.19
- Disclosed:
- Feb 1, 2024
CVE-2023-51674 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 6.9.16
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and M...
- Affected:
- up to 6.9.16
- Fixed in:
- 6.9.16
- Disclosed:
- Dec 29, 2023
CVE-2023-50881 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 6.9.19
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.18.
- Affected:
- up to 6.9.19
- Fixed in:
- 6.9.19
- Disclosed:
- Dec 29, 2023
CVE-2023-51675 on NVD →
Advanced Access Manager <= 6.9.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Advanced Access Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...
- CVSS:
- 6.4
- Affected:
- up to 6.9.18
- Fixed in:
- 6.9.19
- Disclosed:
- Dec 27, 2023
CVE-2023-51674 on NVD →
Advanced Access Manager <= 6.9.18 - Authenticated (Author+) Open Redirect
medium
The Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.9.18. This is due to insufficient validation on the redirect url supplied via params->redirect parameter. This makes it possible for aut...
- CVSS:
- 4.3
- Affected:
- up to 6.9.18
- Fixed in:
- 6.9.19
- Disclosed:
- Dec 27, 2023
CVE-2023-51675 on NVD →
Advanced Access Manager <= 6.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Advanced Access Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to, and including, 6.9.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to...
- CVSS:
- 6.4
- Affected:
- up to 6.9.15
- Fixed in:
- 6.9.16
- Disclosed:
- Dec 26, 2023
CVE-2023-50881 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 6.8.0
unknown
[en] The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 6.8.0
- Fixed in:
- 6.8.0
- Disclosed:
- Nov 23, 2021
CVE-2021-24830 on NVD →
Advanced Access Manager <= 6.7.9 - Admin+ Stored Cross-Site Scripting
medium
The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 4.8
- Affected:
- up to 6.8.0
- Fixed in:
- 6.8.0
- Disclosed:
- Oct 19, 2021
CVE-2021-24830 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 6.6.2
unknown
[en] The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metad...
- Affected:
- up to 6.6.2
- Fixed in:
- 6.6.2
- Disclosed:
- Jan 1, 2021
CVE-2020-35934 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 6.6.2
unknown
[en] The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.)
- Affected:
- up to 6.6.2
- Fixed in:
- 6.6.2
- Disclosed:
- Jan 1, 2021
CVE-2020-35935 on NVD →
Advanced Access Manager <= 6.6.1 - Authenticated Information Disclosure
medium
The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata a...
- CVSS:
- 4.3
- Affected:
- up to 6.6.1
- Fixed in:
- 6.6.2
- Disclosed:
- Aug 20, 2020
CVE-2020-35934 on NVD →
Advanced Access Manager <= 6.6.1 - Authenticated Authorization Bypass and Privilege Escalation
high
The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.)
- CVSS:
- 7.5
- Affected:
- up to 6.6.1
- Fixed in:
- 6.6.2
- Disclosed:
- Aug 14, 2020
CVE-2020-35935 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 2.8.3
unknown
[en] WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- Jan 13, 2020
CVE-2014-6059 on NVD →
Advanced Access Manager <= 5.9.8.1 - Unauthenticated Arbitrary File Read
critical
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php
- CVSS:
- 9.8
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.9
- Disclosed:
- Sep 9, 2019
CVE-2019-25213 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 5.9.9
unknown
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.9
- Disclosed:
- Sep 9, 2019
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 5.9.9
unknown
Arbitrary File Access/Download vulnerability found by "Props to Ov3rfly" in WordPress Advanced Access Manager plugin (versions <= 5.9.8.1).
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.9
- Disclosed:
- Sep 9, 2019
Advanced Access Manager <= 3.2.1 - Unrestricted AJAX Actions allowing Privilege Escalation
high
The Advanced Access Manager plugin for WordPress does not use capability checks on any of its registered AJAX actions. This allows authenticated attackers with any privilege level, including subscribers, to perform actions including elevating their privileges to those of an administrator.
- CVSS:
- 8.8
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.2
- Disclosed:
- Jun 21, 2016
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 3.2.2
unknown
The Advanced Access Manager plugin for WordPress does not use capability checks on any of its registered AJAX actions. This allows authenticated attackers with any privilege level, including subscribers, to perform actions including elevating their privileges to those of an administrator.
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.2
- Disclosed:
- Jun 21, 2016
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 3.2.2
unknown
Because of this vulnerability, users can change their privilege level.
Update the plugin.
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.2
- Disclosed:
- Jun 21, 2016
Advanced Access Manager <= 2.8.2 - Arbitrary File Overwrite
high
WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability
- CVSS:
- 7.2
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- Aug 20, 2014
CVE-2014-6059 on NVD →
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 3.2.2
unknown
Advanced Access Manager does not properly check if a user is authorized to execute AJAX actions, which allows a user to change their privilege level.
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.2
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More [advanced-access-manager] < 5.9.9
unknown
The Advanced Access Manager WordPress plugin, versions before 5.9.9, allowed reading arbitrary files. This way one can download the wp-config.php file and get access to the database, which is publicly reachable on many servers.
The affected function was the printMedia() function in the application/Core/Media.php fil...
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.9