CVE-2020-35934: Vasyltech Advanced Access Manager

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata added by a different plugin).

Affected products

  • Vasyltech Advanced Access Manager: before 6.6.2 (fixed in 6.6.2)

Published 2021-01-01. Last modified 2026-06-17.