Description
WordPress Plugin Advanced Access Manager is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently gain administrator privileges. WordPress Plugin Advanced Access Manager version 3.2.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.2 or latest
References
http://www.pritect.net/blog/advanced-access-manager-3-2-1-security-vulnerability
https://wordpress.org/plugins/advanced-access-manager/changelog/
Related Vulnerabilities
WordPress Plugin PromoBar by BestWebSoft Cross-Site Scripting (1.1.0)
Lighttpd Resource Management Errors Vulnerability (CVE-2012-5533)
WordPress Plugin BuddyPress Multiple Security Bypass Vulnerabilities (7.2.1)
WordPress Plugin WP-CopyProtect [Protect your blog posts] Cross-Site Scripting (3.0.0)
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-0813)