Anti-Malware Security and Brute-Force Firewall
Anti-Malware Security and Brute-Force Firewall has 11 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; all 11 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 9.0 out of 10. Severity breakdown: 1 critical and 4 high. 2022 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Scripting, behind 6 of the records (55%). Other recurring categories include Deserialization Of Untrusted Data, Code Injection.
Every one of the 11 issues recorded for Anti-Malware Security and Brute-Force Firewall has a vendor fix available, so running the current release closes all known holes.
10 independent researchers contributed these findings, most of them (2) reported by James Hooker. Anti-Malware Security and Brute-Force Firewall is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-22144Anti-Malware Security and Brute-Force Firewall <= 4.21.96 - Unauthenticated Remote Code Execution
Read the full analysisVulnerability Records

Anti-Malware Security and Brute-Force Firewall
Author
Eli
Features: Download Definition Updates to protect against new threats. Run a Complete Scan to automatically remove known security threats, backdoor scripts, and database injections. Firewall block SoakSoak and other malware from exploiting Revolution Slider and other plugins with known vulnerabilites. Upgrade vulnerable versions of timthumb scripts. Premium Features: Patch your wp-login and XMLRPC to block Brute-Force and DDoS attacks. Check the integrity of your WordPress Core files. Automatically download new Definition Updates when running a Complete Scan. Register this plugin at GOTMLS.NET and get access to new definitions of “Known Threats” and added features like Automatic Removal, plus patches for specific security vulnerabilities like old versions of timthumb. Updated definition files can be downloaded automatically within the admin once your Key is registered. Otherwise, this plugin just scans for “Potential Threats” and leaves it up to you to identify and remove the malicious ones. NOTICE: This plugin makes calls to GOTMLS.NET to check for updates not unlike what WordPress does when checking your plugins and themes for new versions. Staying up-to-date is an essential part of any security plugin and this plugin can let you know when there are new plugin and definition update available. If you’re allergic to “phone home” scripts then don’t use this plugin (or WordPress at all for that matter). Special thanks to: Clarus Dignus for design suggestions and graphic design work on the banner image. Jelena Kovacevic and Andrew Kurtis of webhostinghub.com for providing the Spanish translation. Marcelo Guernieri for the Brazilian Portuguese translation. Umut Can Alparslan for the Turkish translation. Micha Cassola for the German translation. Robi Erwin Setiawan for the Indonesian translation.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C