CVE-2024-30468
All-In-One Security (AIOS) – Security and Firewall
Minimum safe version
5.2.7
Update to 5.2.7 or later to address 43 fixable vulnerabilities
All In One WP Security <= 5.2.6 - Cross-Site Request Forgery to IP Blocking
CVE-2024-1037
WordPress All In One WP Security & Firewall Plugin <= 5.2.4 is vulnerable to Bypass Vulnerability
All In One WP Security <= 5.2.4 - Protection Bypass of Renamed Login Page via URL Encoding
All-In-One Security (AIOS) – Security and Firewall < 5.2.0 - Insecure Storage of Password
WordPress All In One WP Security & Firewall Plugin 5.1.9 is vulnerable to Sensitive Data Exposure
All In One WP Security 5.1.9 - Plaintext Storage of Credentials
WordPress All In One WP Security & Firewall Plugin < 5.1.5 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-0156
WordPress All In One WP Security & Firewall Plugin <= 5.1.4 is vulnerable to Directory Traversal
All-In-One Security (AIOS) <= 5.1.4 - Authenticated(Admin+) Directory Traversal
All In One WP Security & Firewall <= 4.1.2 - Captcha Bypass
CVE-2022-4346
All In One WP Security & Firewall <= 4.4.3 - Reflected Cross-Site Scripting
All In One WP Security & Firewall 5.0.0 - 5.0.7 - Protection Bypass via IP Spoofing
All In One WP Security & Firewall <= 5.1.0 - Cross-Site Request Forgery
All-In-One Security <= 5.1.2 - Information Disclosure
CVE-2022-4097
CVE-2022-44737
All In One WP Security & Firewall <= 4.1.2 - Multiple vulnerabilities in login CAPTCHA
All In One WP Security & Firewall <= 4.2.1 - Cross-Site Scripting (XSS)
All In One WP Security & Firewall <= 4.4.1 - Open Redirect & Hidden Login Page Exposure
All In One WP Security & Firewall < 4.4.4 - CSRF & XSS
WordPress All In One WP Security & Firewall Plugin 3.9.0 - SQL Injection
WordPress All In One WP Firewall Plugin 3.8.3 - Persistent XSS
WordPress All In One WP Security & Firewall Plugin <= 3.9.7 - XSS
WordPress All In One WP Security & Firewall Plugin <= 4.1.2 - Multiple Vulnerabilities
WordPress All In One WP Security & Firewall <= 4.2.1 - Cross Site Scripting
WordPress All In One WP Security & Firewall plugin <= 4.4.3 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2021-25102
CVE-2014-6242
CVE-2015-0895
CVE-2015-0894
CVE-2016-10868
CVE-2016-10867
CVE-2016-10866
CVE-2015-9294
CVE-2015-9293
CVE-2015-9310
CVE-2016-10888
CVE-2016-10887
WordPress All In One WP Security & Firewall plugin <= 4.4.5 - Authenticated Cross-Site Scripting (XSS) vulnerability