« Back to list

Updraftplus

Updraftplus All-in-one Security: vulnerabilities and CVEs

Updraftplus All-in-one Security has 5 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-1037Medium (6.1)0.55%—Feb 7, 2024
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 5.2.5 due to insufficient input…
CVE-2023-0157Medium (4.8)32%—Apr 10, 2023
The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files…
CVE-2023-0156Medium (4.9)20%—Apr 10, 2023
The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list…
CVE-2022-4346Medium (5.3)0.66%—Jan 23, 2023
The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.
CVE-2022-4097Medium (5.3)0.58%—Dec 12, 2022
The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, brute force protection, and more).

Other products by Updraftplus