CVE-2019-25213

CRITICAL EXPLOITED NUCLEI

WordPress Advanced Access Manager <5.9.8.1 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-25213 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

Nuclei Templates (1)

WordPress Advanced Access Manager - Path Traversal
CRITICALVERIFIEDby riteshs4hu

Scores

CVSS v3 9.8
EPSS 0.0271
EPSS Percentile 84.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2024-10-15
CWE
CWE-22
Status published
Products (2)
vasyltech/Advanced Access Manager – Access Governance for WordPress < 5.9.9
vasyltech/advanced_access_manager < 5.9.8.1
Published Oct 16, 2024
Tracked Since Feb 18, 2026