Extension WordPress
Vulnérabilités All-In-One Security (AIOS) – Security and Firewall
Cette page rassemble les failles publiées pour All-In-One Security (AIOS) – Security and Firewall, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de All-In-One Security (AIOS) – Security and Firewall
27 fiches
All-In-One Security (AIOS) <= 5.4.7 – Unauthenticated Stored Cross-Site Scripting via REST API Request Path
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanitization in the get_rest_route() function and missing output…
*-5.4.7
5.4.8
05/06/2026
All In One WP Security <= 5.2.6 – Cross-Site Request Forgery to IP Blocking
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the render_404_detection() function.…
*-5.2.6
5.2.7
08/02/2024
All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 – Reflected Cross-Site Scripting
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This…
*-5.2.5
5.2.6
06/02/2024
All In One WP Security <= 5.2.4 – Protection Bypass of Renamed Login Page via URL Encoding
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to protection bypass on the login page in all versions up to and including 5.2.4. This makes it possible for unauthenticated attackers to visit the…
[*, 5.2.5)
5.2.5
25/10/2023
All In One WP Security 5.1.9 – Plaintext Storage of Credentials
The All In One WP Security plugin for WordPress is vulnerable to sensitive information disclosure in version 5.1.9. This is due to insufficient encryption on credentials stored in database logs. This makes it possible for attackers to retrieve…
5.1.9
5.2.0
11/07/2023
All-In-One Security (AIOS) <= 5.1.4 – Authenticated (Admin+) Stored Cross-Site Scripting
The All-In-One Security (AIOS) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via log files in versions up to, and including, 5.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-5.1.4
5.1.5
20/03/2023
All-In-One Security (AIOS) <= 5.1.4 – Authenticated(Admin+) Directory Traversal
The All-In-One Security (AIOS) plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 5.1.4. This allows authenticated attackers with administrator-level permissions to read the contents of arbitrary files on the server.
*-5.1.4
5.1.5
14/02/2023
All-In-One Security <= 5.1.2 – Information Disclosure
The All-In-One Security plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 5.1.2. This is due to the plugin allowing administrators to upload backups to publicly accessible folders for restoring purposes. While…
*-5.1.2
5.1.3
09/12/2022
All In One WP Security & Firewall <= 5.1.0 – Cross-Site Request Forgery
The All In One WP Security & Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to incorrect nonce validation on the functions 'render_login_whitelist', 'render_rename_login', 'render_honeypot' functions…
*-5.1.0
5.1.1
22/11/2022
All-In-One Security (AIOS) – Security and Firewall <= 5.0.8 – IP Spoofing to Protection Mechanism Bypass
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.8. This is due to insufficient restrictions on where the IP Address information is being…
*-5.0.7
5.0.8
21/11/2022
All In One WP Security & Firewall <= 5.1.0 – Cross-Site Request Forgery
The All In One WP Security & Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the process_bulk_action function. This…
*-5.1.0
5.1.1
17/11/2022
All In One WP Security & Firewall 5.0.0 – 5.0.7 – Protection Bypass via IP Spoofing
The All In One WP Security & Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions 5.0.0 – 5.0.7 (both included) due to insufficient IP address validation. This makes it possible for attackers to bypass…
5.0.0-5.0.7
5.0.8
30/09/2022
All In One WP Security & Firewall <= 4.4.10 – Open Redirect and Reflected Cross-Site Scripting
The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the…
[*, 4.4.11)
4.4.11
11/04/2022
All In One WP Security & Firewall <= 4.4.5 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.
[*, 4.4.6)
4.4.6
24/12/2020
All In One WP Security & Firewall <= 4.4.3 – Reflected Cross-Site Scripting
The All In One WP Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 4.4.3. This makes it possible for unauthenticated attackers to inject arbitrary…
*-4.4.3
4.4.4
08/09/2020
All In One WP Security & Firewall <= 4.0.8 – SQL Injection
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
[*, 4.0.9)
4.0.9
14/08/2019
All In One WP Security & Firewall <= 4.1.9 – Reflected Cross-Site Scripting
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues via the 'tab' parameter.
[*, 4.2.0)
4.2.0
11/11/2016
All In One WP Security & Firewall <= 4.1.2 – Captcha Bypass
The All In One WP Security & Firewall for WordPress is vulnerable to Captcha Bypass via multiple routes, allowing automated login attempts to proceed
*-4.1.2
4.1.3
31/07/2016
All In One WP Security & Firewall <= 4.0.6 – SQL Injection
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
[*, 4.0.7)
4.0.7
06/04/2016
All In One WP Security & Firewall <= 4.0.5 – Cross-Site Scripting
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
[*, 4.0.6)
4.0.6
23/02/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.