Junglewise Threat Intelligence

CVE-2026-42674: AAM Advanced Access Manager authentication bypass via URL encoding

CVE-2026-42674 · Severity: high · CVSS 7.5 · Published 2026-06-01

Executive brief

Advanced Access Manager is a WordPress plugin used to control user permissions and restrict access to website content. A security flaw in this plugin allows unauthorized users to bypass these access controls by using specially formatted web addresses (URL encoding). This could allow an attacker to view or modify parts of the website that should be restricted, potentially compromising site integrity.

Technical details

The Advanced Access Manager plugin for WordPress (versions up to and including 7.1.0) is vulnerable to an authentication bypass by spoofing (CWE-290). The vulnerability stems from improper handling of URL-encoded characters, which allows an attacker to craft requests that bypass the plugin's access control logic. This is a network-reachable exploit that requires no authentication or user interaction. Successful exploitation allows an attacker to gain unauthorized access to restricted areas or functionalities of the WordPress site. The issue is resolved in version 7.1.1.

Affected products

  • AAM Plugin Advanced Access Manager n/a through 7.1.0

Timeline

  • 2026-04-14: other: Reported by Tiago Ventura
  • 2026-05-14: advisory: Patchstack advisory published
  • 2026-06-01: disclosed: NVD publication date

References