Extension WordPress
Vulnérabilités Advanced Access Manager – Access Governance for WordPress
Cette page rassemble les failles publiées pour Advanced Access Manager – Access Governance for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Advanced Access Manager – Access Governance for WordPress
12 fiches
Advanced Access Manager – Access Governance for WordPress <= 7.1.0 – Missing Authorization
The Advanced Access Manager – Access Governance for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.1.0. This makes it possible…
*-7.1.0
7.1.1
14/05/2026
Advanced Access Manager <= 6.9.20 – Reflected Cross-Site Scripting
The Advanced Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.9.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-6.9.20
6.9.21
20/03/2024
Advanced Access Manager <= 6.9.20 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.9.20 due to insufficient input…
*-6.9.20
6.9.21
16/03/2024
Advanced Access Manager <= 6.9.18 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Advanced Access Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-6.9.18
6.9.19
27/12/2023
Advanced Access Manager <= 6.9.18 – Authenticated (Author+) Open Redirect
The Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.9.18. This is due to insufficient validation on the…
*-6.9.18
6.9.19
27/12/2023
Advanced Access Manager <= 6.9.15 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Advanced Access Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to, and including, 6.9.15 due to insufficient input sanitization and output escaping. This makes it possible for…
*-6.9.15
6.9.16
26/12/2023
Advanced Access Manager <= 6.7.9 – Admin+ Stored Cross-Site Scripting
The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
[*, 6.8.0)
6.8.0
19/10/2021
Advanced Access Manager <= 6.6.1 – Authenticated Information Disclosure
The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the…
*-6.6.1
6.6.2
20/08/2020
Advanced Access Manager <= 6.6.1 – Authenticated Authorization Bypass and Privilege Escalation
The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a…
*-6.6.1
6.6.2
14/08/2020
Advanced Access Manager <= 5.9.8.1 – Unauthenticated Arbitrary File Read
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on…
[*, 5.9.9)
5.9.9
09/09/2019
Advanced Access Manager <= 3.2.1 – Unrestricted AJAX Actions allowing Privilege Escalation
The Advanced Access Manager plugin for WordPress does not use capability checks on any of its registered AJAX actions. This allows authenticated attackers with any privilege level, including subscribers, to perform actions including elevating their privileges to those…
[*, 3.2.2)
3.2.2
21/06/2016
Advanced Access Manager <= 2.8.2 – Arbitrary File Overwrite
WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability
[*, 2.8.3)
2.8.3
20/08/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.