Vulnerabilities > Vasyltech > Advanced Access Manager > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2019-25213 Path Traversal vulnerability in Vasyltech Advanced Access Manager
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter.
network
low complexity
vasyltech CWE-22
7.5
2021-01-01 CVE-2020-35935 Unspecified vulnerability in Vasyltech Advanced Access Manager
The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled.
network
low complexity
vasyltech
8.8
2020-01-13 CVE-2014-6059 Unspecified vulnerability in Vasyltech Advanced Access Manager
WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability
network
low complexity
vasyltech
7.2