WordPress security by component
Advanced Access Manager
Plugin description
Advanced Access Manager is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jun 01, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
advanced-access-managerLatest vulnerability
CVE-2026-42674: Advanced Access Manager: Privilege escalation or authentication bypass
Advanced Access Manager is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 7.1.0.
| Safe version |
|
||
|---|---|---|---|
| Jun 01, 2026 |
CVE-2026-42674
Advanced Access Manager: Privilege escalation or authentication bypass
Advanced Access Manager is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 7.1.0.
|
7.1.1 |
CVE7.5
NVDPending
|
| Oct 16, 2024 |
CVE-2019-25213
Advanced Access Manager: Filesystem traversal
Advanced Access Manager is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE9.8
NVD7.5
|
| Mar 19, 2024 |
CVE-2024-29124
Advanced Access Manager: Cross-site scripting
Advanced Access Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Mar 19, 2024 |
CVE-2024-29127
Advanced Access Manager: Cross-site scripting
Advanced Access Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Feb 01, 2024 |
CVE-2023-51674
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: Cross-site scripting
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Dec 29, 2023 |
CVE-2023-51675
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: An open redirect
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE4.7
NVD5.4
|
| Dec 29, 2023 |
CVE-2023-50881
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: Cross-site scripting
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Nov 23, 2021 |
CVE-2021-24830
Advanced Access Manager: Cross-site scripting
Advanced Access Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Jan 01, 2021 |
CVE-2020-35935
Advanced Access Manager: Privilege escalation or authentication bypass
Advanced Access Manager is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| Jan 01, 2021 |
CVE-2020-35934
Advanced Access Manager: A security weakness
Advanced Access Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jan 13, 2020 |
CVE-2014-6059
Advanced Access Manager: A security weakness
Advanced Access Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.2
NVD7.2
|