Updraftplus
Updraftplus All-in-one Security: vulnerabilities and CVEs
Updraftplus All-in-one Security has 5 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1037 | Medium (6.1) | 0.55% | — | Feb 7, 2024 | The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 5.2.5 due to insufficient input… |
| CVE-2023-0157 | Medium (4.8) | 32% | — | Apr 10, 2023 | The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files… |
| CVE-2023-0156 | Medium (4.9) | 20% | — | Apr 10, 2023 | The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list… |
| CVE-2022-4346 | Medium (5.3) | 0.66% | — | Jan 23, 2023 | The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address. |
| CVE-2022-4097 | Medium (5.3) | 0.58% | — | Dec 12, 2022 | The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, brute force protection, and more). |