plugin

All In One Wp Security And Firewall Vulnerabilities

70 known security issues reported for the All In One Wp Security And Firewall WordPress plugin. Most recent disclosed Jun 5, 2026.

4 critical 4 high 18 medium 1 low

Running All In One Wp Security And Firewall on your site? Check whether your installed version is affected.

Scan your site free

All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path

high

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanitization in the get_rest_route() function and missing output escaping in the column_default() method of the debug log list...

CVSS:
7.2
Affected:
up to 5.4.7
Fixed in:
5.4.8
Disclosed:
Jun 5, 2026

CVE-2026-8438 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.2.5

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects All In One WP Security & Firewall: from n/a through 5.2.4.

Affected:
up to 5.2.5
Fixed in:
5.2.5
Disclosed:
Jun 4, 2024

CVE-2023-52147 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.2.7

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall.This issue affects All In One WP Security & Firewall: from n/a through 5.2.6.

Affected:
up to 5.2.7
Fixed in:
5.2.7
Disclosed:
Mar 29, 2024

CVE-2024-30468 on NVD →

All In One WP Security <= 5.2.6 - Cross-Site Request Forgery to IP Blocking

medium

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the render_404_detection() function. This makes it possible for unauthenticated attackers to block...

CVSS:
4.3
Affected:
up to 5.2.6
Fixed in:
5.2.7
Disclosed:
Feb 8, 2024

CVE-2024-30468 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.2.7

unknown

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the render_404_detection() function. This makes it possible for unauthenticated attackers to block...

Affected:
up to 5.2.7
Fixed in:
5.2.7
Disclosed:
Feb 8, 2024

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.2.6

unknown

[en] The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

Affected:
up to 5.2.6
Fixed in:
5.2.6
Disclosed:
Feb 7, 2024

CVE-2024-1037 on NVD →

All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 - Reflected Cross-Site Scripting

medium

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...

CVSS:
6.1
Affected:
up to 5.2.5
Fixed in:
5.2.6
Disclosed:
Feb 6, 2024

CVE-2024-1037 on NVD →

All In One WP Security <= 5.2.4 - Protection Bypass of Renamed Login Page via URL Encoding

medium

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to protection bypass on the login page in all versions up to and including 5.2.4. This makes it possible for unauthenticated attackers to visit the login page in cases where it has been renamed by using URL Encoding to visit wp-lo...

CVSS:
5.3
Affected:
up to 5.2.5
Fixed in:
5.2.5
Disclosed:
Oct 25, 2023

CVE-2023-52147 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.2.5

unknown

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to protection bypass on the login page in all versions up to and including 5.2.4. This makes it possible for unauthenticated attackers to visit the login page in cases where it has been renamed by using URL Encoding to visit wp-lo...

Affected:
up to 5.2.5
Fixed in:
5.2.5
Disclosed:
Oct 25, 2023

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.2.0

unknown

Update the WordPress All In One WP Security & Firewall plugin to the latest available version (at least 5.2.0). Unknown discovered and reported this Sensitive Data Exposure vulnerability in WordPress All In One WP Security & Firewall Plugin. This vulnerability has been fixed in version 5.2.0.

Affected:
up to 5.2.0
Fixed in:
5.2.0
Disclosed:
Jul 12, 2023

All In One WP Security 5.1.9 - Plaintext Storage of Credentials

medium

The All In One WP Security plugin for WordPress is vulnerable to sensitive information disclosure in version 5.1.9. This is due to insufficient encryption on credentials stored in database logs. This makes it possible for attackers to retrieve the username and password of users that have logged into the site, granted t...

CVSS:
5.9
Affected:
5.1.9 – 5.1.9
Fixed in:
5.2.0
Disclosed:
Jul 11, 2023

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.2.0

unknown

The All In One WP Security plugin for WordPress is vulnerable to sensitive information disclosure in version 5.1.9. This is due to insufficient encryption on credentials stored in database logs. This makes it possible for attackers to retrieve the username and password of users that have logged into the site, granted t...

Affected:
up to 5.2.0
Fixed in:
5.2.0
Disclosed:
Jul 11, 2023

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.1.5

unknown

[en] The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to which the web server has access). The plugin only displays the l...

Affected:
up to 5.1.5
Fixed in:
5.1.5
Disclosed:
Apr 10, 2023

CVE-2023-0156 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.1.5

unknown

[en] The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting...

Affected:
up to 5.1.5
Fixed in:
5.1.5
Disclosed:
Apr 10, 2023

CVE-2023-0157 on NVD →

All-In-One Security (AIOS) <= 5.1.4 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The All-In-One Security (AIOS) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via log files in versions up to, and including, 5.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inje...

CVSS:
4.4
Affected:
up to 5.1.4
Fixed in:
5.1.5
Disclosed:
Mar 20, 2023

CVE-2023-0157 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.1.5

unknown

Update the WordPress All In One WP Security & Firewall plugin to the latest available version (at least 5.1.5). Unknown discovered and reported this Directory Traversal vulnerability in WordPress All In One WP Security & Firewall Plugin. This could allow a malicious actor to see all files in a given directory or determ...

Affected:
up to 5.1.5
Fixed in:
5.1.5
Disclosed:
Feb 15, 2023

All-In-One Security (AIOS) <= 5.1.4 - Authenticated(Admin+) Directory Traversal

medium

The All-In-One Security (AIOS) plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 5.1.4. This allows authenticated attackers with administrator-level permissions to read the contents of arbitrary files on the server.

CVSS:
4.9
Affected:
up to 5.1.4
Fixed in:
5.1.5
Disclosed:
Feb 14, 2023

CVE-2023-0156 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.1.5

unknown

The All-In-One Security (AIOS) plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 5.1.4. This allows authenticated attackers with administrator-level permissions to read the contents of arbitrary files on the server.

Affected:
up to 5.1.5
Fixed in:
5.1.5
Disclosed:
Feb 14, 2023

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.1.3

unknown

[en] The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.

Affected:
up to 5.1.3
Fixed in:
5.1.3
Disclosed:
Jan 23, 2023

CVE-2022-4346 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.0.8

unknown

[en] The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, brute force protection, and more).

Affected:
up to 5.0.8
Fixed in:
5.0.8
Disclosed:
Dec 12, 2022

CVE-2022-4097 on NVD →

All-In-One Security <= 5.1.2 - Information Disclosure

medium

The All-In-One Security plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 5.1.2. This is due to the plugin allowing administrators to upload backups to publicly accessible folders for restoring purposes. While under normal use these files would be deleted as part of the res...

CVSS:
5.3
Affected:
up to 5.1.2
Fixed in:
5.1.3
Disclosed:
Dec 9, 2022

CVE-2022-4346 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.1.3

unknown

The All-In-One Security plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 5.1.2. This is due to the plugin allowing administrators to upload backups to publicly accessible folders for restoring purposes. While under normal use these files would be deleted as part of the res...

Affected:
up to 5.1.3
Fixed in:
5.1.3
Disclosed:
Dec 9, 2022

All In One WP Security & Firewall <= 5.1.0 - Cross-Site Request Forgery

high

The All In One WP Security & Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to incorrect nonce validation on the functions 'render_login_whitelist', 'render_rename_login', 'render_honeypot' functions and possible others. This makes it possi...

CVSS:
8.8
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Nov 22, 2022

CVE-2022-44737 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.1.1

unknown

[en] Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Nov 22, 2022

CVE-2022-44737 on NVD →

All-In-One Security (AIOS) – Security and Firewall <= 5.0.8 - IP Spoofing to Protection Mechanism Bypass

medium

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.8. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X...

CVSS:
6.5
Affected:
up to 5.0.7
Fixed in:
5.0.8
Disclosed:
Nov 21, 2022

CVE-2022-4097 on NVD →

All In One WP Security & Firewall <= 5.1.0 - Cross-Site Request Forgery

high

The All In One WP Security & Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to modify the plugin's block list...

CVSS:
8.8
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Nov 17, 2022

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.1.1

unknown

The All In One WP Security & Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to modify the plugin's block list...

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Nov 17, 2022

All In One WP Security & Firewall 5.0.0 - 5.0.7 - Protection Bypass via IP Spoofing

medium

The All In One WP Security & Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions 5.0.0 - 5.0.7 (both included) due to insufficient IP address validation. This makes it possible for attackers to bypass IP blocks and access services even if their IP address is blocked.

CVSS:
6.5
Affected:
5.0.0 – 5.0.7
Fixed in:
5.0.8
Disclosed:
Sep 30, 2022

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.0.8

unknown

The All In One WP Security & Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions 5.0.0 - 5.0.7 (both included) due to insufficient IP address validation. This makes it possible for attackers to bypass IP blocks and access services even if their IP address is blocked.

Affected:
up to 5.0.8
Fixed in:
5.0.8
Disclosed:
Sep 30, 2022

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.4.11

unknown

[en] The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cro...

Affected:
up to 4.4.11
Fixed in:
4.4.11
Disclosed:
May 2, 2022

CVE-2021-25102 on NVD →

All In One WP Security & Firewall <= 4.4.10 - Open Redirect and Reflected Cross-Site Scripting

medium

The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Si...

CVSS:
6.1
Affected:
up to 4.4.11
Fixed in:
4.4.11
Disclosed:
Apr 11, 2022

CVE-2021-25102 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.4.6

unknown

[en] Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.

Affected:
up to 4.4.6
Fixed in:
4.4.6
Disclosed:
Feb 10, 2021

CVE-2020-29171 on NVD →

All In One WP Security & Firewall <= 4.4.5 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.

CVSS:
6.1
Affected:
up to 4.4.6
Fixed in:
4.4.6
Disclosed:
Dec 24, 2020

CVE-2020-29171 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.4.4

unknown

Reflected Cross-Site Scripting (XSS) vulnerability found by Antony Garand (Sucuri) in WordPress All In One WP Security & Firewall plugin (versions <= 4.4.3).

Affected:
up to 4.4.4
Fixed in:
4.4.4
Disclosed:
Sep 9, 2020

All In One WP Security & Firewall <= 4.4.3 - Reflected Cross-Site Scripting

medium

The All In One WP Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 4.4.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully tric...

CVSS:
4.7
Affected:
up to 4.4.3
Fixed in:
4.4.4
Disclosed:
Sep 8, 2020

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.4.4

unknown

The All In One WP Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 4.4.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully tric...

Affected:
up to 4.4.4
Fixed in:
4.4.4
Disclosed:
Sep 8, 2020

All In One WP Security & Firewall <= 4.0.8 - SQL Injection

critical

The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.

CVSS:
9.8
Affected:
up to 4.0.9
Fixed in:
4.0.9
Disclosed:
Aug 14, 2019

CVE-2016-10887 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 3.9.1

unknown

[en] The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.

Affected:
up to 3.9.1
Fixed in:
3.9.1
Disclosed:
Aug 14, 2019

CVE-2015-9310 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.0.9

unknown

[en] The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.

Affected:
up to 4.0.9
Fixed in:
4.0.9
Disclosed:
Aug 14, 2019

CVE-2016-10887 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.0.7

unknown

[en] The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.

Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Aug 14, 2019

CVE-2016-10888 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.0.5

unknown

[en] The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.

Affected:
up to 4.0.5
Fixed in:
4.0.5
Disclosed:
Aug 13, 2019

CVE-2016-10868 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.2.0

unknown

[en] The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.

Affected:
up to 4.2.0
Fixed in:
4.2.0
Disclosed:
Aug 13, 2019

CVE-2016-10866 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.0.6

unknown

[en] The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.

Affected:
up to 4.0.6
Fixed in:
4.0.6
Disclosed:
Aug 13, 2019

CVE-2016-10867 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 3.9.8

unknown

[en] The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.

Affected:
up to 3.9.8
Fixed in:
3.9.8
Disclosed:
Aug 13, 2019

CVE-2015-9293 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 3.9.5

unknown

[en] The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.

Affected:
up to 3.9.5
Fixed in:
3.9.5
Disclosed:
Aug 13, 2019

CVE-2015-9294 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.2.2

unknown

This plugin is prone to a cross site scripting vulnerability. Update the plugin.

Affected:
up to 4.2.2
Fixed in:
4.2.2
Disclosed:
Dec 14, 2016

All In One WP Security & Firewall <= 4.1.9 - Reflected Cross-Site Scripting

medium

The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues via the 'tab' parameter.

CVSS:
6.1
Affected:
up to 4.2.0
Fixed in:
4.2.0
Disclosed:
Nov 11, 2016

CVE-2016-10866 on NVD →

All In One WP Security & Firewall <= 4.1.2 - Captcha Bypass

medium

The All In One WP Security & Firewall for WordPress is vulnerable to Captcha Bypass via multiple routes, allowing automated login attempts to proceed

CVSS:
5.3
Affected:
up to 4.1.2
Fixed in:
4.1.3
Disclosed:
Jul 31, 2016

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.1.3

unknown

There are multiple vulnerabilities in in login CAPTCHA. Because of them, attackers can automate login attempts when the CAPTCHA is enabled. Update the plugin.

Affected:
up to 4.1.3
Fixed in:
4.1.3
Disclosed:
Jul 31, 2016

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.1.3

unknown

The All In One WP Security & Firewall for WordPress is vulnerable to Captcha Bypass via multiple routes, allowing automated login attempts to proceed

Affected:
up to 4.1.3
Fixed in:
4.1.3
Disclosed:
Jul 31, 2016

All In One WP Security & Firewall <= 4.0.6 - SQL Injection

critical

The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.

CVSS:
9.8
Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Apr 6, 2016

CVE-2016-10888 on NVD →

All In One WP Security & Firewall <= 4.0.5 - Cross-Site Scripting

medium

The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.

CVSS:
6.1
Affected:
up to 4.0.6
Fixed in:
4.0.6
Disclosed:
Feb 23, 2016

CVE-2016-10867 on NVD →

All In One WP Security & Firewall <= 4.0.4 - Cross-Site Scripting

medium

The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.

CVSS:
6.1
Affected:
up to 4.0.5
Fixed in:
4.0.5
Disclosed:
Feb 22, 2016

CVE-2016-10868 on NVD →

All In One WP Security & Firewall <= 3.9.7 - Cross-Site Scripting

medium

The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.

CVSS:
6.1
Affected:
up to 3.9.8
Fixed in:
3.9.8
Disclosed:
Aug 15, 2015

CVE-2015-9293 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 3.9.8

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 3.9.8
Fixed in:
3.9.8
Disclosed:
Aug 13, 2015

All In One WP Security & Firewall <= 3.9.4 - Reflected Cross-Site Scripting

medium

The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.

CVSS:
6.1
Affected:
up to 3.9.5
Fixed in:
3.9.5
Disclosed:
Apr 20, 2015

CVE-2015-9294 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 3.9.1

unknown

This WordPress All In One WP Security & Firewall plugin's "esc_sql" function is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 3.9.1
Fixed in:
3.9.1
Disclosed:
Apr 8, 2015

All In One WP Security & Firewall <= 3.9.0 - SQL Injection

critical

The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.

CVSS:
9.8
Affected:
up to 3.9.1
Fixed in:
3.9.1
Disclosed:
Apr 6, 2015

CVE-2015-9310 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 3.9.0

unknown

[en] Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete logs of 404 (aka Not Found) HTTP status codes.

Affected:
up to 3.9.0
Fixed in:
3.9.0
Disclosed:
Mar 7, 2015

CVE-2015-0895 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 3.8.8

unknown

[en] SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Affected:
up to 3.8.8
Fixed in:
3.8.8
Disclosed:
Mar 7, 2015

CVE-2015-0894 on NVD →

All In One WP Security & Firewall <= 3.8.7 - SQL Injection

critical

SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS:
9
Affected:
up to 3.8.8
Fixed in:
3.8.8
Disclosed:
Mar 6, 2015

CVE-2015-0894 on NVD →

All In One WP Security & Firewall <= 3.8.9 - Cross-Site Request Forgery

low

Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete logs of 404 (aka Not Found) HTTP status codes.

CVSS:
3.1
Affected:
up to 3.8.9
Fixed in:
3.9.0
Disclosed:
Mar 6, 2015

CVE-2015-0895 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 3.8.3

unknown

[en] Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allo...

Affected:
up to 3.8.3
Fixed in:
3.8.3
Disclosed:
Oct 2, 2014

CVE-2014-6242 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 3.8.4

unknown

WordPress All In One WP Firewall plugin is prone to a persistent XSS vulnerability. It results session hijacking, persistent external redirect to malicious sources, persistent phishing attacks and application-side manipulation of affected module context. Update the plugin.

Affected:
up to 3.8.4
Fixed in:
3.8.4
Disclosed:
Oct 2, 2014

All In One WP Security & Firewall <= 3.8.2 - Authenticated Access or Cross-Site Request Forgery leading to SQL Injection via orderby, order Parameters

high

Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow rem...

CVSS:
7.4
Affected:
up to 3.8.3
Fixed in:
3.8.3
Disclosed:
Sep 24, 2014

CVE-2014-6242 on NVD →

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.4.4

unknown

Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack. The vulnerability affecting the All In One WP Security &amp; Firewall plugin required the victim to be...

Affected:
up to 4.4.4
Fixed in:
4.4.4

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 5.2.0

unknown

The plugin stores the password inside the database as plaintext allowing administrators to obtain access to user&#039;s passwords.

Affected:
up to 5.2.0
Fixed in:
5.2.0

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.4.2

unknown

The All In One WP Security &amp; Firewall plugin suffers from open redirect and exposure of the actual URL of the &quot;hidden login page&quot; feature. Edit (WPScanTeam) October 3rd, 2019 - Email sent to dev via https://wpsolutions-hq.com/contact/ October 8th - Dev ACK &amp; investigating it October 8th - v4.4.2...

Affected:
up to 4.4.2
Fixed in:
4.4.2

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.2.2

unknown

The All In One WP Security &amp; Firewall WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 4.2.2
Fixed in:
4.2.2

All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] < 4.1.3

unknown

The All In One WP Security &amp; Firewall WordPress plugin was affected by a Multiple vulnerabilities in login CAPTCHA security vulnerability.

Affected:
up to 4.1.3
Fixed in:
4.1.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database