PT-2021-11868 · WordPress · Aam Advanced Access Manager

Ramuel Gall

·

Published

2021-01-01

·

Updated

2024-01-05

·

CVE-2020-35934

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Advanced Access Manager plugin versions prior to 6.6.2
Description: The issue arises when the Advanced Access Manager plugin for WordPress displays the unfiltered user object, including all metadata, upon login via the REST API at endpoints "aam/v1/authenticate" or "aam/v2/authenticate". This poses a security problem if the user object stores information that the user is not supposed to have, such as custom metadata added by a different plugin.
Recommendations: For versions prior to 6.6.2, update to version 6.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API endpoints "aam/v1/authenticate" and "aam/v2/authenticate" to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2020-35934

Affected Products

Aam Advanced Access Manager