All In One WP Security 5.1.9 - Plaintext Storage of Credentials
Strategic Overview
- Status
- Patched in 5.2.0
- Affected Plugin
- All-In-One Security (AIOS) – Security and Firewall
- Affected Version
5.1.9- CVSS
- 5.9Medium
- Weakness type
- CWE-256 · Plaintext Storage of a Password
- CVE
CVE pending
At a glance
This record tracks a medium-severity Plaintext Storage of a Password vulnerability in the All-In-One Security (AIOS) WordPress plugin, affecting versions 5.1.9. It carries a CVSS score of 5.9 (reachable over the network; high confidentiality impact). Exploitation requires no authentication. The issue is fixed in version 5.2.0; sites on affected versions should update now. Disclosed July 2023.
Vulnerability Overview
The All In One WP Security plugin for WordPress is vulnerable to sensitive information disclosure in version 5.1.9. This is due to insufficient encryption on credentials stored in database logs. This makes it possible for attackers to retrieve the username and password of users that have logged into the site, granted they obtain access to the database which would require successfully exploiting another vulnerability such as SQL injection or use of weak passwords.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, and no privileges on the target site, and no interaction from a victim user. A successful exploit has high impact on confidentiality.
CWE-256: Plaintext Storage of a Password
The product stores a password in plaintext within resources such as memory or files.
Remediation
Update to version 5.2.0, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: All-In-One Security (AIOS) 5.2.0 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in All-In-One Security (AIOS) – Security and Firewall
- 9.8CVE-2016-10887: All In One WP Security & Firewall SQL Injection
CVE-2016-10887 - 9.8CVE-2016-10888: All In One WP Security & Firewall SQL Injection
CVE-2016-10888 - 9.8CVE-2015-9310: All In One WP Security & Firewall SQL Injection
CVE-2015-9310 - 9.0CVE-2015-0894: All In One WP Security & Firewall SQL Injection
CVE-2015-0894 - 8.8CVE-2022-44737: All In One WP Security & Firewall <= 5.1.0 CSRF
CVE-2022-44737 - 8.8All In One WP Security & Firewall <= 5.1.0 Cross-Site Request Forgery
- 7.4CVE-2014-6242: All In One WP Security & Firewall Access or CSRF
CVE-2014-6242 - 7.2CVE-2026-8438: All-In-One Security (AIOS) <= 5.4.7 Stored XSS
CVE-2026-8438
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C