PT-2021-11869 · WordPress · Aam Advanced Access Manager

Published

2021-01-01

·

Updated

2024-01-05

·

CVE-2020-35935

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Advanced Access Manager plugin versions prior to 6.6.2 for WordPress
Description: The issue allows privilege escalation on profile updates via the aam user roles POST parameter if Multiple Role support is enabled. The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.
Recommendations: For versions prior to 6.6.2, update to version 6.6.2 or later to resolve the issue. As a temporary workaround, consider disabling the Multiple Role support feature until a patch is available. Restrict access to profile updates to minimize the risk of exploitation. Avoid using the aam user roles parameter in profile updates until the issue is resolved.

Exploit

Fix

Related Identifiers

CVE-2020-35935

Affected Products

Aam Advanced Access Manager