Anti-Malware Security and Brute-Force Firewall <= 4.23.89 - Unauthenticated Stored Cross-Site Scripting
high
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.23.89 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...
- CVSS:
- 7.2
- Affected:
- up to 4.23.89
- Fixed in:
- 4.23.90
- Disclosed:
- Jul 9, 2026
CVE-2026-57691 on NVD →
Anti-Malware Security and Brute-Force Firewall <= 4.23.87 - Authenticated (Contributor+) PHP Object Injection
high
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.23.87 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known PO...
- CVSS:
- 7.5
- Affected:
- up to 4.23.87
- Fixed in:
- 4.23.88
- Disclosed:
- Apr 20, 2026
CVE-2026-39478 on NVD →
Anti-Malware Security and Brute-Force Firewall <= 4.23.81 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read
medium
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.23.81 due to a missing capability check combined with an information exposure in several GOTMLS_* AJAX actions. This makes it possible for authenticated attackers, with Su...
- CVSS:
- 6.5
- Affected:
- up to 4.23.81
- Fixed in:
- 4.23.83
- Disclosed:
- Oct 28, 2025
CVE-2025-11705 on NVD →
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.56
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through 4.21.96.
- Affected:
- up to 4.23.56
- Fixed in:
- 4.23.56
- Disclosed:
- Apr 25, 2024
CVE-2024-22144 on NVD →
Anti-Malware Security and Brute-Force Firewall <= 4.21.96 - Unauthenticated Remote Code Execution
critical
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.21.96 due to weak nonce generation combined with missing authorization. This makes it possible for unauthenticated attackers to brute force a valid nonce that can be use...
- CVSS:
- 9
- Affected:
- up to 4.21.96
- Fixed in:
- 4.23.56
- Disclosed:
- Mar 12, 2024
CVE-2024-22144 on NVD →
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.86
unknown
- Affected:
- up to 4.21.86
- Fixed in:
- 4.21.86
- Disclosed:
- Jan 16, 2023
CVE-2022-4327 on NVD →
Anti-Malware Security and Brute-Force Firewall <= 4.21.85 - Authenticated (Admin+) PHP Object Injection
high
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.21.85 via deserialization of untrusted input. This allows attackers, with administrative privileges, to inject a PHP Object. No POP chain is present in the vulnerable plugin....
- CVSS:
- 7.2
- Affected:
- up to 4.21.85
- Fixed in:
- 4.21.86
- Disclosed:
- Dec 21, 2022
CVE-2022-4327 on NVD →
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.86
unknown
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.21.85 via deserialization of untrusted input. This allows attackers, with administrative privileges, to inject a PHP Object. No POP chain is present in the vulnerable plugin....
- Affected:
- up to 4.21.86
- Fixed in:
- 4.21.86
- Disclosed:
- Dec 21, 2022
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.21.83
unknown
[en] The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting
- Affected:
- up to 4.21.83
- Fixed in:
- 4.21.83
- Disclosed:
- Aug 29, 2022
CVE-2022-2599 on NVD →
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.20.96
unknown
[en] The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters
- Affected:
- up to 4.20.96
- Fixed in:
- 4.20.96
- Disclosed:
- Apr 25, 2022
CVE-2022-0953 on NVD →
Anti-Malware Security and Brute-Force Firewall <= 4.20.95 - Reflected Cross-Site Scripting
medium
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters
- CVSS:
- 6.1
- Affected:
- up to 4.20.96
- Fixed in:
- 4.20.96
- Disclosed:
- Apr 11, 2022
CVE-2022-0953 on NVD →
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.20.94
unknown
[en] The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can on...
- Affected:
- up to 4.20.94
- Fixed in:
- 4.20.94
- Disclosed:
- Feb 21, 2022
CVE-2021-25101 on NVD →
Anti-Malware Security and Brute-Force Firewall <= 4.21.74 - Reflected Cross-Site Scripting
medium
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'GOTMLS_debug' parameter in versions up to, and including, 4.21.74 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...
- CVSS:
- 6.1
- Affected:
- up to 4.21.74
- Fixed in:
- 4.21.83
- Disclosed:
- Feb 8, 2022
CVE-2022-2599 on NVD →
Anti-Malware Security and Brute-Force Firewall <= 4.20.93 - Reflected Cross-Site Scripting
medium
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only be...
- CVSS:
- 6.1
- Affected:
- up to 4.20.94
- Fixed in:
- 4.20.94
- Disclosed:
- Jan 24, 2022
CVE-2021-25101 on NVD →
Anti-Malware Security and Brute-Force Firewall <= 4.15.17 - Cross-Site Scripting
high
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.15.17 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.2
- Affected:
- up to 4.15.17
- Fixed in:
- 4.16.18
- Disclosed:
- May 10, 2016
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.16.18
unknown
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.15.17 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 4.16.18
- Fixed in:
- 4.16.18
- Disclosed:
- May 10, 2016
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.43
unknown
This plugin is prone to a cross site scripting and cross site request forgery vulnerabilities.
Update the plugin.
- Affected:
- up to 4.15.43
- Fixed in:
- 4.15.43
- Disclosed:
- Apr 23, 2016
Anti-Malware Security and Brute-Force Firewall [gotmls] < 1.2.07.20
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.2.07.20
- Fixed in:
- 1.2.07.20
- Disclosed:
- May 26, 2015
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 4.15.23
- Fixed in:
- 4.15.23
- Disclosed:
- May 26, 2015
Anti-Malware Security and Brute-Force Firewall [gotmls] < 1.2.07.20
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.2.07.20
- Fixed in:
- 1.2.07.20
- Disclosed:
- May 26, 2015
Anti-Malware Security and Brute-Force Firewall <= 4.15.22 - Cross-Site Scripting
medium
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.15.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers, if they trick an administrator to visiting a fo...
- CVSS:
- 6.1
- Affected:
- up to 4.15.23
- Fixed in:
- 4.15.23
- Disclosed:
- May 25, 2015
Anti-Malware Security and Brute-Force Firewall <= 4.15.22 - Cross-Site Request Forgery
low
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.22. This makes it possible for unauthenticated attackers to consume resource utilization (by performing a large number of scans simultaneously), via forged request...
- CVSS:
- 3.1
- Affected:
- up to 4.15.23
- Fixed in:
- 4.15.23
- Disclosed:
- May 25, 2015
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23
unknown
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.15.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers, if they trick an administrator to visiting a fo...
- Affected:
- up to 4.15.23
- Fixed in:
- 4.15.23
- Disclosed:
- May 25, 2015
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23
unknown
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.22. This makes it possible for unauthenticated attackers to consume resource utilization (by performing a large number of scans simultaneously), via forged request...
- Affected:
- up to 4.15.23
- Fixed in:
- 4.15.23
- Disclosed:
- May 25, 2015
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.20
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 4.15.20
- Fixed in:
- 4.15.20
- Disclosed:
- May 15, 2015
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.44
unknown
The Anti-Malware Security and Brute-Force Firewall WordPress plugin was affected by a XSS & CSRF security vulnerability.
- Affected:
- up to 4.15.44
- Fixed in:
- 4.15.44
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.23
unknown
The Anti-Malware and Brute-Force Security by ELI has two issues which we will cover in this report. The first is that no nonce (CSRF token) is utilized on the settings screen.
This could potentially result in resource utilization (by performing a large number of scans simultaneously), should an administrative user...
- Affected:
- up to 4.15.23
- Fixed in:
- 4.15.23
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.15.20
unknown
The Anti-Malware Security and Brute-Force Firewall WordPress plugin was affected by a Multiple Reflected XSS security vulnerability.
- Affected:
- up to 4.15.20
- Fixed in:
- 4.15.20
Anti-Malware Security and Brute-Force Firewall [gotmls] < 1.2.07.20
unknown
The Anti-Malware Security and Brute-Force Firewall WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.2.07.20
- Fixed in:
- 1.2.07.20
Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.83
unknown
- Affected:
- up to 4.23.83
- Fixed in:
- 4.23.83
CVE-2025-11705 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database