Skip to main content

Vendor/product archive

updraftplus / all-in-one_security CVEs

Beta · best-effort

5 CVEs tagged to updraftplus / all-in-one_security0 Critical, 0 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2024-1037

Published Feb 7, 2024

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and incl…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-0157

Published Apr 10, 2023

The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (a…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-0156

Published Apr 10, 2023

The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the cont…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4346

Published Jan 23, 2023

The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4097

Published Dec 12, 2022

The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, br…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1