CVE-2019-25213

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
16/10/2024
Last modified:
30/10/2024

Description

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vasyltech:advanced_access_manager:*:*:*:*:*:wordpress:*:* 5.9.8.1 (including)