Extension WordPress

Vulnérabilités All-In-One Security (AIOS) – Security and Firewall

Cette page rassemble les failles publiées pour All-In-One Security (AIOS) – Security and Firewall, leurs plages de versions affectées et les correctifs signalés dans la base locale.

27Vulnérabilités
4Critiques
27Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de All-In-One Security (AIOS) – Security and Firewall

27 fiches

CVE-2026-8438 Élevée · 7,2
All-In-One Security (AIOS) – Security and Firewall

All-In-One Security (AIOS) <= 5.4.7 – Unauthenticated Stored Cross-Site Scripting via REST API Request Path

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanitization in the get_rest_route() function and missing output…

Versions affectées

*-5.4.7

Correctif

5.4.8

Publication

05/06/2026

CVE-2024-30468 Moyenne · 4,3
All-In-One Security (AIOS) – Security and Firewall

All In One WP Security <= 5.2.6 – Cross-Site Request Forgery to IP Blocking

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the render_404_detection() function.…

Versions affectées

*-5.2.6

Correctif

5.2.7

Publication

08/02/2024

CVE-2024-1037 Moyenne · 6,1
All-In-One Security (AIOS) – Security and Firewall

All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 – Reflected Cross-Site Scripting

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-5.2.5

Correctif

5.2.6

Publication

06/02/2024

CVE-2023-52147 Moyenne · 5,3
All-In-One Security (AIOS) – Security and Firewall

All In One WP Security <= 5.2.4 – Protection Bypass of Renamed Login Page via URL Encoding

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to protection bypass on the login page in all versions up to and including 5.2.4. This makes it possible for unauthenticated attackers to visit the…

Versions affectées

[*, 5.2.5)

Correctif

5.2.5

Publication

25/10/2023

CVE-2023-0157 Moyenne · 4,4
All-In-One Security (AIOS) – Security and Firewall

All-In-One Security (AIOS) <= 5.1.4 – Authenticated (Admin+) Stored Cross-Site Scripting

The All-In-One Security (AIOS) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via log files in versions up to, and including, 5.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-5.1.4

Correctif

5.1.5

Publication

20/03/2023

CVE-2023-0156 Moyenne · 4,9
All-In-One Security (AIOS) – Security and Firewall

All-In-One Security (AIOS) <= 5.1.4 – Authenticated(Admin+) Directory Traversal

The All-In-One Security (AIOS) plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 5.1.4. This allows authenticated attackers with administrator-level permissions to read the contents of arbitrary files on the server.

Versions affectées

*-5.1.4

Correctif

5.1.5

Publication

14/02/2023

CVE-2022-44737 Élevée · 8,8
All-In-One Security (AIOS) – Security and Firewall

All In One WP Security & Firewall <= 5.1.0 – Cross-Site Request Forgery

The All In One WP Security & Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to incorrect nonce validation on the functions 'render_login_whitelist', 'render_rename_login', 'render_honeypot' functions…

Versions affectées

*-5.1.0

Correctif

5.1.1

Publication

22/11/2022

CVE-2022-4097 Moyenne · 6,5
All-In-One Security (AIOS) – Security and Firewall

All-In-One Security (AIOS) – Security and Firewall <= 5.0.8 – IP Spoofing to Protection Mechanism Bypass

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.8. This is due to insufficient restrictions on where the IP Address information is being…

Versions affectées

*-5.0.7

Correctif

5.0.8

Publication

21/11/2022

Vulnérabilité Moyenne · 6,5
All-In-One Security (AIOS) – Security and Firewall

All In One WP Security & Firewall 5.0.0 – 5.0.7 – Protection Bypass via IP Spoofing

The All In One WP Security & Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions 5.0.0 – 5.0.7 (both included) due to insufficient IP address validation. This makes it possible for attackers to bypass…

Versions affectées

5.0.0-5.0.7

Correctif

5.0.8

Publication

30/09/2022

CVE-2021-25102 Moyenne · 6,1
All-In-One Security (AIOS) – Security and Firewall

All In One WP Security & Firewall <= 4.4.10 – Open Redirect and Reflected Cross-Site Scripting

The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the…

Versions affectées

[*, 4.4.11)

Correctif

4.4.11

Publication

11/04/2022

Vulnérabilité Moyenne · 4,7
All-In-One Security (AIOS) – Security and Firewall

All In One WP Security & Firewall <= 4.4.3 – Reflected Cross-Site Scripting

The All In One WP Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 4.4.3. This makes it possible for unauthenticated attackers to inject arbitrary…

Versions affectées

*-4.4.3

Correctif

4.4.4

Publication

08/09/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités