{"error":0,"message":null,"data":{"name":"Advanced Access Manager \u2013 Access Governance for WordPress","plugin":"advanced-access-manager","link":"https:\/\/wordpress.org\/plugins\/advanced-access-manager\/","latest":"1788863160","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"33f8e9302005c9cf4f15bfa49b1719f2dbd2e5355df896ace8465aab8a10eede","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 6.8.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.8.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24830","name":"CVE-2021-24830","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24830","description":"[en] The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed","date":"2021-11-23"},{"id":"46bf31d777ffb44f3ba59be5a89a97c57826d547","name":"WordPress Advanced Access Manager plugin <= 6.7.9 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-6-7-9-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability discovered by Huy Nguyen in WordPress Advanced Access Manager plugin (versions <= 6.7.9).","date":"2021-10-19"},{"id":"1c46373b-d43d-4d18-b0ae-3711fb0be0f9","name":"Advanced Access Manager &lt; 6.8.0 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/1c46373b-d43d-4d18-b0ae-3711fb0be0f9","description":"The plugin does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed","date":null},{"id":"642e49bec784b004281dfa3736ddfa6c43dde6a1","name":"Advanced Access Manager <= 6.7.9 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-679-admin-stored-cross-site-scripting","description":"The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed","date":"2021-10-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"9c7744df6e4fcab71d721c915abcb60f237d15fdb017a617e6642d999a2291b6","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 6.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-35934","name":"CVE-2020-35934","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-35934","description":"[en] The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam\/v1\/authenticate or aam\/v2\/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata added by a different plugin).","date":"2021-01-01"},{"id":"fb3e4221fc6cf0e07f62d924f7d62b5ab484b622","name":"WordPress Advanced Access Manager plugin <= 6.6.1 - Authenticated Information Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-6-6-1-authenticated-information-disclosure-vulnerability","description":"Authenticated Information Disclosure vulnerability discovered by WordFence in WordPress Advanced Access Manager plugin (versions <= 6.6.1).","date":"2020-04-20"},{"id":"8108a873-2b97-46fd-a269-2a259dd5b23e","name":"Advanced Access Manager &lt; 6.6.2 - Authenticated Information Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/8108a873-2b97-46fd-a269-2a259dd5b23e","description":"The plugin&rsquo;s aam\/v1\/authenticate and aam\/v2\/authenticate REST endpoints were set to respond to a successful login with a json-encoded copy of all metadata about the user, potentially exposing users&rsquo; information to an attacker or low-privileged user. This included items like the user&rsquo;s hashed password and their capabilities and roles, as well as any custom metadata that might have been added by other plugins. This might include sensitive configuration information, which an attacker could potentially use as part of an exploit chain.","date":null},{"id":"675cde2e43924e2250a69221754e05cbc8ed52bc","name":"Advanced Access Manager <= 6.6.1 - Authenticated Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-661-authenticated-information-disclosure","description":"The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam\/v1\/authenticate or aam\/v2\/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata added by a different plugin).","date":"2020-08-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"111cfa07d5c4afe277b05bb364ed47fcf74697e7b0fde791e201533f6ffe5c86","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 6.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-35935","name":"CVE-2020-35935","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-35935","description":"[en] The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.)","date":"2021-01-01"},{"id":"c0780741069cd4e3c5fd2696595af5dda43c3167","name":"WordPress Advanced Access Manager plugin <= 6.6.1 - Authenticated Authorization Bypass and Privilege Escalation vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-6-6-1-authenticated-authorization-bypass-and-privilege-escalation-vulnerability","description":"Authenticated Authorization Bypass and Privilege Escalation vulnerability discovered by WordFence in WordPress Advanced Access Manager plugin (versions <= 6.6.1).","date":"2020-04-20"},{"id":"235844c1-e3f6-4f42-a8cf-f9a661873656","name":"Advanced Access Manager &lt; 6.6.2 - Authenticated Authorization Bypass and Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/235844c1-e3f6-4f42-a8cf-f9a661873656","description":"A low-privileged user could assign themselves or switch to any role with an equal or lesser user level, or any role that did not have an assigned user level. This could be done by sending a POST request to wp-admin\/profile.php with typical profile update parameters and appending a aam_user_roles[] parameter set to the role they would like to use.","date":null},{"id":"58691747489a4ddbab6d3ae4aeac5316326b1c76","name":"Advanced Access Manager <= 6.6.1 - Authenticated Authorization Bypass and Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-661-authenticated-authorization-bypass-and-privilege-escalation","description":"The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.)","date":"2020-08-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"}}},{"uuid":"63a144cb1db4c264d1666d2a40a1f3a58737a24128eedfdf7c8c18d273938cca","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 2.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-6059","name":"CVE-2014-6059","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-6059","description":"[en] WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability","date":"2020-01-13"},{"id":"f54855e60f7ff88804d6567378f5647ed86ed851","name":"WordPress Advanced Access Manager Plugin <= 2.8.2 - Admin User File Read\/Write","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-2-8-2-admin-user-file-read-write","description":"Because of this vulnerability, attackers can write arbitrary content to arbitrary files.\nUpdate the plugin.","date":"2014-09-27"},{"id":"10a1719a-28c3-4213-a55d-24f7d4efd821","name":"Advanced Access Manager 2.8.2 - Admin User File Read\/Write","link":"https:\/\/wpscan.com\/vulnerability\/10a1719a-28c3-4213-a55d-24f7d4efd821","description":"The Advanced Access Manager WordPress plugin was affected by an Admin User File Read\/Write security vulnerability.","date":null},{"id":"7e78f571d5adff8f655016b9beee401407dcd99e","name":"Advanced Access Manager <= 2.8.2 - Arbitrary File Overwrite","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-282-arbitrary-file-overwrite","description":"WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability","date":"2014-08-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"}}},{"uuid":"d6067171f55e332f8cdf30ff3d60ddc547a804becff7d494a56243b9153a89db","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 5.9.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e065cf88395987fcdeb7e91bf1689b5793b7035d","name":"WordPress Advanced Access Manager plugin <= 5.9.8.1 - Arbitrary File Access\/Download vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-5-9-8-1-arbitrary-file-access-download-vulnerability","description":"Arbitrary File Access\/Download vulnerability found by \"Props to Ov3rfly\" in WordPress Advanced Access Manager plugin (versions <= 5.9.8.1).","date":"2019-09-09"}],"impact":[]},{"uuid":"6fe8d0d94a89b8a795571416f217feaa5d3f703994cb9f287f6e6e706242ea3f","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 3.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"df8f1a703bc1eee5faa6a1ca5eb7ceacfa99db27","name":"WordPress Advanced Access Manager Plugin <= 3.3 - Unrestricted File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-3-3-unrestricted-file-upload","description":"Because of this vulnerability, users can change their privilege level.\nUpdate the plugin.","date":"2016-06-21"}],"impact":[]},{"uuid":"f6e53a872bd16443d24f3c44e67b0f1f10dcc280c9533fa79489b41f9e3c0eca","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 5.9.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dfe62ff5-956c-4403-b3fd-55677628036b","name":"Advanced Access Manager &lt; 5.9.9 - Unauthenticated Local File Inclusion","link":"https:\/\/wpscan.com\/vulnerability\/dfe62ff5-956c-4403-b3fd-55677628036b","description":"The Advanced Access Manager WordPress plugin, versions before 5.9.9, allowed reading arbitrary files. This way one can download the wp-config.php file and get access to the database, which is publicly reachable on many servers.\r\n\r\nThe affected function was the printMedia() function in the application\/Core\/Media.php file.","date":null}],"impact":[]},{"uuid":"8f2d725f570e818dcdc039ce5791a72a9ec861a1abfdf09442532986897bc37e","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 3.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c93dea0f-27a4-474e-9ee4-38fdb4fbc588","name":"Advanced Access Manager &lt;= 3.2.1 - Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/c93dea0f-27a4-474e-9ee4-38fdb4fbc588","description":"Advanced Access Manager does not properly check if a user is authorized to execute AJAX actions, which allows a user to change their privilege level.","date":null}],"impact":[]},{"uuid":"ce5baf8ae0a97c5aaf2848cc8674c5c6dc202ed2730b2812a528aacaae6e9b7d","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 5.9.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0cd7404aea43a9c6fc6a7a3bad099f28ab0de861","name":"Advanced Access Manager <= 5.9.8.1 - Unauthenticated Arbitrary File Read","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-5981-unauthenticated-arbitrary-file-read","description":"The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php","date":"2019-09-09"},{"id":"CVE-2019-25213","name":"CVE-2019-25213","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-25213","description":"[en] The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php","date":"2024-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"3f0268f5e720fa74aaebe02ec4bb12f286b80aaa404dab3fffbeb222e12e6215","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 3.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c80c75d43520fcf1ef44a682d2ac3404f9ac0188","name":"Advanced Access Manager <= 3.2.1 - Unrestricted AJAX Actions allowing Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-321-unrestricted-ajax-actions-allowing-privilege-escalation","description":"The Advanced Access Manager plugin for WordPress does not use capability checks on any of its registered AJAX actions. This allows authenticated attackers with any privilege level, including subscribers, to perform actions including elevating their privileges to those of an administrator.","date":"2016-06-21"}],"impact":[]},{"uuid":"3d48abb5d5615e07df1d452d301fc431f8b26f25a4525ec9fbaa607c85c8b42a","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 6.9.19","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.9.19","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-51674","name":"CVE-2023-51674","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-51674","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager \u2013 Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager \u2013 Restricted Content, Users & Roles, Enhanced Security and More: from n\/a through 6.9.18.","date":"2024-02-01"},{"id":"f89630f11bb1026acf319083115fdefef0c4a454","name":"WordPress  Advanced Access Manager Plugin  <= 6.9.18 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-6-9-18-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Advanced Access Manager plugin to the latest available version (at least 6.9.19).\nLVT-tholv2k discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Access Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.9.19.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-27"},{"id":"34812c86dbc58eaa3d7dd3d233b7379cfb25c79b","name":"Advanced Access Manager <= 6.9.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-6918-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Advanced Access Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-27"},{"id":"7618d6ac-d3b6-469b-947b-4e4c92a153a5","name":"Advanced Access Manager &lt; 6.9.19 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/7618d6ac-d3b6-469b-947b-4e4c92a153a5","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2902e5a11a4f550f2821f752e8ad483e64df88f54ff3a95b04539a4ef6c16462","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 6.9.19","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.9.19","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-51675","name":"CVE-2023-51675","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-51675","description":"[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager \u2013 Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager \u2013 Restricted Content, Users & Roles, Enhanced Security and More: from n\/a through 6.9.18.","date":"2023-12-29"},{"id":"f050f49d3d8c232f9cc54957642605e57af515cb","name":"WordPress  Advanced Access Manager Plugin  <= 6.9.18 is vulnerable to Open Redirection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-6-9-18-open-redirection-vulnerability","description":"Update the WordPress Advanced Access Manager plugin to the latest available version (at least 6.9.19).\nLVT-tholv2k discovered and reported this Open Redirection vulnerability in WordPress Advanced Access Manager Plugin. This could allow a malicious actor to redirect users from one site to the other due to the redirect URL not being validated. Users could be tricked to visiting a legitimate site to then be redirected to a malicious site and cause a phishing incident. This vulnerability has been fixed in version 6.9.19.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-27"},{"id":"d338b42c91caae946ff9583859f6217402772bf9","name":"Advanced Access Manager <= 6.9.18 - Authenticated (Author+) Open Redirect","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-6918-authenticated-author-open-redirect","description":"The Advanced Access Manager \u2013 Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.9.18. This is due to insufficient validation on the redirect url supplied via params->redirect parameter. This makes it possible for authenticated attackers (author and higher) to redirect users to potentially malicious sites if they can successfully trick them into performing an action such as logging in.","date":"2023-12-27"},{"id":"dd79d748-2dcb-41fa-acd1-327f57f13029","name":"Advanced Access Manager &lt; 6.9.19 - Open Redirect","link":"https:\/\/wpscan.com\/vulnerability\/dd79d748-2dcb-41fa-acd1-327f57f13029","description":"The plugin is vulnerable to Open Redirect due to insufficient validation on the redirect url supplied via params-&gt;redirect parameter. This makes it possible for authenticated attackers (author and higher) to redirect users to potentially malicious sites if they can successfully trick them into performing an action such as logging in.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"n","a":"n","score":"4.7","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:N\/A:N","score":"4.7","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"none","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"aeec153241537f36db05665ae35f023e290f6b22d67ab2f271240f42cfb8831a","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 6.9.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.9.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-50881","name":"CVE-2023-50881","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-50881","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager \u2013 Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager \u2013 Restricted Content, Users & Roles, Enhanced Security and More: from n\/a through 6.9.15.","date":"2023-12-29"},{"id":"ca3f7cefc2025b2f21103c209b8b6bdf533db633","name":"WordPress  Advanced Access Manager Plugin  <= 6.9.15 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-6-9-15-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Advanced Access Manager plugin to the latest available version (at least 6.9.16).\nNg\u00f4 Thi\u00ean An (ancorn_ from VNPT-VCI) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Access Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.9.16.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-26"},{"id":"fef625ff48b976b46d94c03fab6fcff51be46917","name":"Advanced Access Manager <= 6.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-6915-authenticated-contributor-stored-cross-site-scripting","description":"The Advanced Access Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to, and including, 6.9.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-26"},{"id":"cba86685-b667-4039-810e-94c7ca8ac7c3","name":"Advanced Access Manager &lt; 6.9.16 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/cba86685-b667-4039-810e-94c7ca8ac7c3","description":"The plugin does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e0b2406fe72e934687a38684092e6dee20e25319ef28a15219abedcc97915ceb","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 6.9.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.9.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-29124","name":"CVE-2024-29124","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-29124","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Stored XSS.This issue affects Advanced Access Manager: from n\/a through 6.9.20.","date":"2024-03-19"},{"id":"c9b07436272c785cca7aa44246ee43c29a958bb6","name":"WordPress  Advanced Access Manager Plugin    <= 6.9.20 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-6-9-20-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Advanced Access Manager plugin to the latest available version (at least 6.9.21).\nDelbert Giovanni Lie discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Access Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.9.21.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"efbd8f1799a8107cef70dca3676893c65212c9f8","name":"Advanced Access Manager <= 6.9.20 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-6920-authenticated-administrator-stored-cross-site-scripting","description":"The Advanced Access Manager \u2013 Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-03-16"},{"id":"ab08429d-213f-4690-af5d-36c7fcc13512","name":"Advanced Access Manager &lt; 6.9.21 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/ab08429d-213f-4690-af5d-36c7fcc13512","description":"The plugin does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"1.7","impact":"3.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"1.7","impact":"3.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2659f9cd78cb5fb7dc362ccaf48d9d0f19f59bda8fac1c440497bd58786a929c","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 6.9.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.9.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-29127","name":"CVE-2024-29127","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-29127","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Reflected XSS.This issue affects Advanced Access Manager: from n\/a through 6.9.20.","date":"2024-03-19"},{"id":"a9430037286729eda349496eb6c0ff13631b07b3","name":"WordPress  Advanced Access Manager Plugin    <= 6.9.20 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-6-9-20-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Advanced Access Manager plugin to the latest available version (at least 6.9.21).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Access Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.9.21.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"345791bfd482fd443fa918ed059cfab263476cc9","name":"Advanced Access Manager <= 6.9.20 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-6920-reflected-cross-site-scripting","description":"The Advanced Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.9.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-03-20"},{"id":"14de56a0-3570-4dc8-9b1a-c721bf8d128a","name":"Advanced Access Manager &lt; 6.9.21 - Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/14de56a0-3570-4dc8-9b1a-c721bf8d128a","description":"The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7ff5c6f5694524c9fa2df731bed14b5cb6783f7a45db49a4eff0f7f0335fa476","name":"Advanced Access Manager \u2013 Access Governance for WordPress [advanced-access-manager] < 7.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-42674","name":"CVE-2026-42674","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-42674","description":"[en] Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding.\n\nThis issue affects Advanced Access Manager: from n\/a through 7.1.0.","date":"2026-06-01"},{"id":"36b5bcfc8d05f168615bf2c3ab28decbc48bf734","name":"WordPress Advanced Access Manager Plugin <= 7.1.0 is vulnerable to Bypass Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/advanced-access-manager\/vulnerability\/wordpress-advanced-access-manager-plugin-7-1-0-bypass-vulnerability-vulnerability","description":"<p>WordPress Advanced Access Manager Plugin <= 7.1.0 is vulnerable to Bypass Vulnerability<\/p><p>Software: Advanced Access Manager<\/p><p>Fixed in version 7.1.1 <\/p><p>Affected Version <= 7.1.0<\/p><p>CVE: CVE-2026-42674<\/p>","date":"2026-05-14"},{"id":"99da33b8b491b9dcb108be8f0e1a9a1e4febc907","name":"Advanced Access Manager \u2013 Access Governance for WordPress <= 7.1.0 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/advanced-access-manager\/advanced-access-manager-access-governance-for-wordpress-710-missing-authorization","description":"The Advanced Access Manager \u2013 Access Governance for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-05-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-290","name":"Authentication Bypass by Spoofing","description":"This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1779083350"}