โ† Back to browse ยท API

CVE-2019-25213

Severity
CRITICAL
CVSS
9.8
EPSS
0.02772
Risk score
40.17
CISA KEV
No
PoC
No
Published
2024-10-16
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2019-19361, GHSA-WX98-RPCR-JRWV
Products
vasyltech:Advanced Access Manager โ€“ Access Governance for WordPress 0 <5.9.9
Sources
euvd EUVD-2019-19361

Description

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

References