cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foradvanced-access-manager advanced-access-manager

Direction: ascending
Jun 07, 2024

Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More # CVE-2021-24830

CVE, Research URL

CVE-2021-24830

Date
Nov 24, 2021
Research Description
The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Affected versions
max 6.8.0.
Status
vulnerable

Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More # CVE-2020-35935

CVE, Research URL

CVE-2020-35935

Date
Jan 01, 2021
Research Description
The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.)
Affected versions
max 6.6.2.
Status
vulnerable

Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More # CVE-2020-35934

CVE, Research URL

CVE-2020-35934

Date
Jan 01, 2021
Research Description
The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata added by a different plugin).
Affected versions
max 6.6.2.
Status
vulnerable

Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More # CVE-2023-51675

CVE, Research URL

CVE-2023-51675

Date
Dec 29, 2023
Research Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.18.
Affected versions
max 6.9.19.
Status
vulnerable

Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More # CVE-2023-50881

CVE, Research URL

CVE-2023-50881

Date
Dec 29, 2023
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.15.
Affected versions
max 6.9.16.
Status
vulnerable

Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More # CVE-2024-29124

CVE, Research URL

CVE-2024-29124

Date
Mar 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Stored XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20.
Affected versions
max 6.9.21.
Status
vulnerable

Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More # CVE-2023-51674

CVE, Research URL

CVE-2023-51674

Date
Feb 01, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.18.
Affected versions
max 6.9.19.
Status
vulnerable

Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More # CVE-2024-29127

CVE, Research URL

CVE-2024-29127

Date
Mar 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Reflected XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20.
Affected versions
max 6.9.21.
Status
vulnerable
Oct 17, 2024

Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More # CVE-2019-25213

CVE, Research URL

CVE-2019-25213

Date
Oct 16, 2024
Research Description
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php
Affected versions
max 5.9.9.
Status
vulnerable
May 19, 2026