PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 1, 2025

WordPress Advanced Access Manager - Path Traversal

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
7
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-25213
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Advanced Access Manager – Access Governance for WordPressby vasyltech
AFFECTED< 5.9.9SAFE ✓≥ 5.9.9
advanced_access_managerby advanced_access_manager_project
AFFECTED< 5.9.9SAFE ✓≥ 5.9.9
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

WordPress Advanced Access Manager - Path Traversal CVE-2019-25213 Scanner | S4E