WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Advanced Access Manager – Access Governance for WordPress

Access Governance for WordPress. Control roles, users, content, admin areas, and APIs to prevent broken access controls and excessive privileges.

12Reported vulnerabilities
8.8Highest CVSS score
7.1.2Latest version
100,000+Active installs

What to do now

Update Advanced Access Manager – Access Governance for WordPress to 7.1.1 or later. 12 of these have a fixed version available. Updating resolves them.

Plugin last updated: May 25, 2026 / Tested up to WordPress: 7.0.0 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2020-35935 High 8.8 1.5% Before 6.6.2 6.6.2 January 1, 2021
CVE-2014-6059 High 7.2 3.3% Before 2.8.2 2.8.2 January 13, 2020
CVE-2021-24830 Medium 4.8 0.7% Before 6.8.0 6.8.0 November 23, 2021
CVE-2020-35934 Medium 4.3 1.1% Before 6.6.2 6.6.2 January 1, 2021
WF-8530affb-0b6e-4b71-acab-3561cccc1855 High 8.8 Before 3.2.2 3.2.2 June 21, 2016
CVE-2019-25213 High 7.5 2.8% 5.9.8.1 and earlier 5.9.9 October 16, 2024
CVE-2023-51674 Medium 6.4 0.3% 6.9.18 and earlier 6.9.19 December 27, 2023
CVE-2023-50881 Medium 6.4 0.3% 6.9.15 and earlier 6.9.16 December 26, 2023
CVE-2024-29127 Medium 6.1 0.4% 6.9.20 and earlier 6.9.21 March 20, 2024
CVE-2024-29124 Medium 5.5 0.4% 6.9.20 and earlier 6.9.21 March 16, 2024
CVE-2026-42674 Medium 5.3 0.4% 7.1.0 and earlier 7.1.1 May 14, 2026
CVE-2023-51675 Medium 4.3 0.3% 6.9.18 and earlier 6.9.19 December 27, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.