The Advanced Access Manager plugin before 6.6.2 for...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 5, 2024
Description
Published by the National Vulnerability Database
Jan 1, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 5, 2024
The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata added by a different plugin).
References