Record summary

CVE-2019-25213 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 15, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Advanced Access Manager plugin for WordPress

Browse AAM / Advanced Access Manager plugin for WordPress
VulnCheckVersion data not supplied

Default status: unknown

CVE ListBefore 5.9.9affected

Advanced Access Manager – Access Governance for WordPress

Browse vasyltech / Advanced Access Manager – Access Governance for WordPress

Default status: unaffected

CVE ListBefore 5.9.9affected

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Advanced Access Manager - Path TraversalCVSS 9.8

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

Impact

Unauthenticated attackers can read sensitive files like wp-config.php, leading to information disclosure and potential further exploitation.

Remediation

Update to the latest version of the plugin that addresses this vulnerability.

WeaknessesCWE-264
Authorsriteshs4hu
Template tagscvecve2019wordpresswp-pluginwpadvanced_access_managerlfivkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: ProjectDiscovery

References

3