QID 730857
Date Published: 2023-07-27
QID 730857: WordPress Plugin Advanced Access Manager Arbitrary File Access/Download Vulnerability
Advanced Access Manager is a WordPress plugin that gives you the ability to manage access to your website content for any role, individual user and visitors or even define the default access to all posts, pages, custom post types, categories etc.
This plugin suffers from a Arbitrary File Access/Download vulnerability.
Affected Version:
All versions prior to 5.9.9
QID Detection Logic:
The QID send a request to endpoint, along with the payload and looks for a pattern in the response, in order to confirm the vulnerability.
Successful exploitation of the vulnerability could completely compromise the confidentiality of the application.
Solution
Customers are advised to upgrade to Advanced Access Manager Plugin version 5.9.9 or later version to remediate this vulnerability.
Vendor References
- Advanced Access Manager Plugin Release Notes -
wordpress.org/plugins/advanced-access-manager/#developers
CVEs related to QID 730857
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Advanced Access Manager Plugin Release Notes |
|