All In One WP Security 5.1.9 - Plaintext Storage of Credentials
Strategic Overview
5.1.9N/AVulnerability Overview
The All In One WP Security plugin for WordPress is vulnerable to sensitive information disclosure in version 5.1.9. This is due to insufficient encryption on credentials stored in database logs. This makes it possible for attackers to retrieve the username and password of users that have logged into the site, granted they obtain access to the database which would require successfully exploiting another vulnerability such as SQL injection or use of weak passwords.
Technical Analysis
REMEDIATION: Update to version 5.2.0, or a newer patched version --- IDENTIFIER: CWE-256 (Plaintext Storage of a Password) The product stores a password in plaintext within resources such as memory or files.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C