Files
CVEs-PoC/2019/CVE-2019-25213.md
2025-09-29 21:09:30 +02:00

1.2 KiB

CVE-2019-25213

Description

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

POC

Reference

No PoCs from references.

Github