Impact
The WordPress Advanced Access Manager plugin contains a flaw that allows an attacker to spoof authentication tokens by manipulating URL‑encoded parameters. This weakness, classified as CWE‑290, lets a remote user bypass the plugin’s authentication checks and gain unauthorized access to protected content or administrative interfaces.
Affected Systems
Any WordPress site that has installed the Advanced Access Manager plugin in a version through 7.1.0, from the earliest release up to and including that version, is affected. The plugin is identified under the vendor name AAM Plugin:Advanced Access Manager.
Risk and Exploitability
The CVSS score of 7.5 categorises the issue as high severity. Although a specific EPSS value is not available and the vulnerability is not listed in CISA’s KEV catalog, the simplicity of the exploit—requiring only a crafted URL—to bypass authentication makes exploitation likely in a suitable environment. The attack vector is remote, with an adversary accessing the target WordPress site via a specially formatted request that circumvents the plugin’s security controls.
OpenCVE Enrichment