plugin

Gotmls Vulnerabilities

30 known security issues reported for the Gotmls WordPress plugin. Most recent disclosed Jul 9, 2026.

1 critical 4 high 5 medium 1 low

Running Gotmls on your site? Check whether your installed version is affected.

Scan your site free

Anti-Malware Security and Brute-Force Firewall <= 4.23.89 - Unauthenticated Stored Cross-Site Scripting

high

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.23.89 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...

CVSS:
7.2
Affected:
up to 4.23.89
Fixed in:
4.23.90
Disclosed:
Jul 9, 2026

CVE-2026-57691 on NVD →

Anti-Malware Security and Brute-Force Firewall <= 4.23.87 - Authenticated (Contributor+) PHP Object Injection

high

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.23.87 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known PO...

CVSS:
7.5
Affected:
up to 4.23.87
Fixed in:
4.23.88
Disclosed:
Apr 20, 2026

CVE-2026-39478 on NVD →

Anti-Malware Security and Brute-Force Firewall <= 4.23.81 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read

medium

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.23.81 due to a missing capability check combined with an information exposure in several GOTMLS_* AJAX actions. This makes it possible for authenticated attackers, with Su...

CVSS:
6.5
Affected:
up to 4.23.81
Fixed in:
4.23.83
Disclosed:
Oct 28, 2025

CVE-2025-11705 on NVD →

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.56

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through 4.21.96.

Affected:
up to 4.23.56
Fixed in:
4.23.56
Disclosed:
Apr 25, 2024

CVE-2024-22144 on NVD →

Anti-Malware Security and Brute-Force Firewall <= 4.21.96 - Unauthenticated Remote Code Execution

critical

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.21.96 due to weak nonce generation combined with missing authorization. This makes it possible for unauthenticated attackers to brute force a valid nonce that can be use...

CVSS:
9
Affected:
up to 4.21.96
Fixed in:
4.23.56
Disclosed:
Mar 12, 2024

CVE-2024-22144 on NVD →

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.86

unknown
Affected:
up to 4.21.86
Fixed in:
4.21.86
Disclosed:
Jan 16, 2023

CVE-2022-4327 on NVD →

Anti-Malware Security and Brute-Force Firewall <= 4.21.85 - Authenticated (Admin+) PHP Object Injection

high

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.21.85 via deserialization of untrusted input. This allows attackers, with administrative privileges, to inject a PHP Object. No POP chain is present in the vulnerable plugin....

CVSS:
7.2
Affected:
up to 4.21.85
Fixed in:
4.21.86
Disclosed:
Dec 21, 2022

CVE-2022-4327 on NVD →

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.86

unknown

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.21.85 via deserialization of untrusted input. This allows attackers, with administrative privileges, to inject a PHP Object. No POP chain is present in the vulnerable plugin....

Affected:
up to 4.21.86
Fixed in:
4.21.86
Disclosed:
Dec 21, 2022

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.83

unknown

[en] The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting

Affected:
up to 4.21.83
Fixed in:
4.21.83
Disclosed:
Aug 29, 2022

CVE-2022-2599 on NVD →

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.20.96

unknown

[en] The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

Affected:
up to 4.20.96
Fixed in:
4.20.96
Disclosed:
Apr 25, 2022

CVE-2022-0953 on NVD →

Anti-Malware Security and Brute-Force Firewall <= 4.20.95 - Reflected Cross-Site Scripting

medium

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

CVSS:
6.1
Affected:
up to 4.20.96
Fixed in:
4.20.96
Disclosed:
Apr 11, 2022

CVE-2022-0953 on NVD →

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.20.94

unknown

[en] The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can on...

Affected:
up to 4.20.94
Fixed in:
4.20.94
Disclosed:
Feb 21, 2022

CVE-2021-25101 on NVD →

Anti-Malware Security and Brute-Force Firewall <= 4.21.74 - Reflected Cross-Site Scripting

medium

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'GOTMLS_debug' parameter in versions up to, and including, 4.21.74 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...

CVSS:
6.1
Affected:
up to 4.21.74
Fixed in:
4.21.83
Disclosed:
Feb 8, 2022

CVE-2022-2599 on NVD →

Anti-Malware Security and Brute-Force Firewall <= 4.20.93 - Reflected Cross-Site Scripting

medium

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only be...

CVSS:
6.1
Affected:
up to 4.20.94
Fixed in:
4.20.94
Disclosed:
Jan 24, 2022

CVE-2021-25101 on NVD →

Anti-Malware Security and Brute-Force Firewall <= 4.15.17 - Cross-Site Scripting

high

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.15.17 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.2
Affected:
up to 4.15.17
Fixed in:
4.16.18
Disclosed:
May 10, 2016

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.16.18

unknown

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.15.17 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 4.16.18
Fixed in:
4.16.18
Disclosed:
May 10, 2016

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.43

unknown

This plugin is prone to a cross site scripting and cross site request forgery vulnerabilities. Update the plugin.

Affected:
up to 4.15.43
Fixed in:
4.15.43
Disclosed:
Apr 23, 2016

Anti-Malware Security and Brute-Force Firewall [gotmls] < 1.2.07.20

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.2.07.20
Fixed in:
1.2.07.20
Disclosed:
May 26, 2015

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 4.15.23
Fixed in:
4.15.23
Disclosed:
May 26, 2015

Anti-Malware Security and Brute-Force Firewall [gotmls] < 1.2.07.20

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.2.07.20
Fixed in:
1.2.07.20
Disclosed:
May 26, 2015

Anti-Malware Security and Brute-Force Firewall <= 4.15.22 - Cross-Site Scripting

medium

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.15.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers, if they trick an administrator to visiting a fo...

CVSS:
6.1
Affected:
up to 4.15.23
Fixed in:
4.15.23
Disclosed:
May 25, 2015

Anti-Malware Security and Brute-Force Firewall <= 4.15.22 - Cross-Site Request Forgery

low

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.22. This makes it possible for unauthenticated attackers to consume resource utilization (by performing a large number of scans simultaneously), via forged request...

CVSS:
3.1
Affected:
up to 4.15.23
Fixed in:
4.15.23
Disclosed:
May 25, 2015

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23

unknown

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.15.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers, if they trick an administrator to visiting a fo...

Affected:
up to 4.15.23
Fixed in:
4.15.23
Disclosed:
May 25, 2015

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23

unknown

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.22. This makes it possible for unauthenticated attackers to consume resource utilization (by performing a large number of scans simultaneously), via forged request...

Affected:
up to 4.15.23
Fixed in:
4.15.23
Disclosed:
May 25, 2015

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.20

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 4.15.20
Fixed in:
4.15.20
Disclosed:
May 15, 2015

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.44

unknown

The Anti-Malware Security and Brute-Force Firewall WordPress plugin was affected by a XSS &amp; CSRF security vulnerability.

Affected:
up to 4.15.44
Fixed in:
4.15.44

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23

unknown

The Anti-Malware and Brute-Force Security by ELI has two issues which we will cover in this report. The first is that no nonce (CSRF token) is utilized on the settings screen. This could potentially result in resource utilization (by performing a large number of scans simultaneously), should an administrative user...

Affected:
up to 4.15.23
Fixed in:
4.15.23

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.20

unknown

The Anti-Malware Security and Brute-Force Firewall WordPress plugin was affected by a Multiple Reflected XSS security vulnerability.

Affected:
up to 4.15.20
Fixed in:
4.15.20

Anti-Malware Security and Brute-Force Firewall [gotmls] < 1.2.07.20

unknown

The Anti-Malware Security and Brute-Force Firewall WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.2.07.20
Fixed in:
1.2.07.20

Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.83

unknown
Affected:
up to 4.23.83
Fixed in:
4.23.83

CVE-2025-11705 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database