Advanced Access Manager – Access Governance for WordPress
Advanced Access Manager – Access Governance for WordPress has 12 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2026; all 12 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2023 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 5 of the records (42%). Other recurring categories include Path Traversal, Authentication Bypass By Primary Weakness.
Every one of the 12 issues recorded for Advanced Access Manager – Access Governance for WordPress has a vendor fix available, so running the current release closes all known holes.
10 independent researchers contributed these findings, most of them (2) reported by LVT-tholv2k. Advanced Access Manager – Access Governance for WordPress is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.0.
CVE-2019-25213Advanced Access Manager <= 5.9.8.1 - Unauthenticated Arbitrary File Read
Read the full analysisVulnerability Records

Advanced Access Manager – Access Governance for WordPress
Author
AAM Plugin
Advanced Access Manager (AAM) introduces Access Governance for WordPress – a systematic approach to securing your site by controlling who can access what, when, and why. Most WordPress security plugins focus on external threats like malware, firewalls, and brute-force attacks. AAM addresses the root cause of the #1 WordPress security risk: broken access controls, excessive privileges, and misconfigured roles. Instead of reacting to attacks, AAM helps you design security into your WordPress site. What Access Governance means in practice Mitigate Broken Access Controls. Ensure roles, users, and permissions are correctly configured to prevent unauthorized actions and privilege escalation. Eliminate Excessive Privileges. Identify overpowered users and reduce access to critical functionality, admin areas, and APIs. Secure Content by Design. Control who can view, edit, publish, or delete posts, pages, media, taxonomies, and custom content types. Govern Access with Policy. Define access rules using JSON Access Policies — portable, auditable, and automation-friendly. Build Custom Security Logic. Use the AAM PHP Framework to create advanced, programmatic access controls tailored to your application. Key Features Security Audit. Detect risky role assignments, misconfigurations, and compromised accounts. Granular Access Control. Manage permissions for any user, role, or visitor with precision. Role & Capability Management. Customize WordPress roles and capabilities beyond defaults. Admin & Menu Control. Restrict dashboard areas and tailor the admin experience per user or role. API & Endpoint Protection. Secure REST and XML-RPC access with fine-grained controls. Modern Authentication Options. Support passwordless and secure login flows. Developer-Ready Framework. Extend WordPress security using AAM’s powerful SDK. Ad-Free & Transparent. – No ads, no tracking, no bloat. Built for Security-Conscious WordPress Users AAM is trusted by 150,000+ websites to deliver enterprise-grade access control without unnecessary complexity. Whether you’re a site owner, agency, developer, or security professional, AAM gives you full control over WordPress access — by design. Most core features are free. Advanced capabilities are available via premium add-ons. No hidden tracking. No data collection. No unwanted changes. Just security you can reason about, audit, and trust.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C