Advanced Access Manager <= 5.9.8.1 - Unauthenticated Arbitrary File Read
Published Oct 16, 2024
9.8
CRITICALCVSS 3.1
EPSS 2.77%
Description
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php
Affected products
- Vendor Vasyltech Product Advanced Access Manager – Access Governance for WordPress Defaultunaffected
- Version 0StatusaffectedConstraints<5.9.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Vasyltech | Advanced Access Manager – Access Governance for WordPress | unaffected |
|
- ≤ 5.9.8.1
-
- Version 0StatusaffectedConstraints<5.9.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Advanced Access Manager Project | Advanced Access Manager | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Oct 16, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.77% (0.02772) | 85.81th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.71% (0.02711) | 84.00th | v5 (v2026.06.15) |
| May 22, 2026 | 43.19% (0.43187) | 97.55th | v4 (v2025.03.14) |
| Apr 29, 2026 | 40.16% (0.40156) | 97.35th | v4 (v2025.03.14) |
| Mar 7, 2026 | 46.13% (0.46131) | 97.57th | v4 (v2025.03.14) |
| Dec 18, 2025 | 39.58% (0.39580) | 97.15th | v4 (v2025.03.14) |
| Dec 2, 2025 | 44.61% (0.44607) | 97.43th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.67% (0.02673) | 84.50th | v4 (v2025.03.14) |
| Aug 12, 2025 | 1.54% (0.01538) | 80.56th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.34% (0.00337) | 53.50th | v4 (v2025.03.14) |
| Mar 29, 2025 | 21.68% (0.21685) | 93.06th | v4 (v2025.03.14) |
| Mar 24, 2025 | 0.30% (0.00302) | 50.50th | v4 (v2025.03.14) |
| Mar 23, 2025 | 3.53% (0.03532) | 85.41th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.28% (0.00276) | 49.01th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.09% (0.00090) | 40.12th | v3 (v2023.03.01) |
| Oct 17, 2024 | 0.09% (0.00091) | 40.06th | v3 (v2023.03.01) |
References (2)
- https://plugins.trac.wordpress.org/changeset/2098838/advanced-access-manager/trunk/application/Core/Media.php?old=2151316&old_path=advanced-access-manager%2Ftrunk%2Fapplication%2FCore%2FMedia.php Patch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/55e0f0df-7be2-4e18-988c-2cc558768eff?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.