Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2022-44737

Disclosure Date: November 22, 2022 (last updated November 08, 2023)
Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.
Attacker Value
Unknown

CVE-2022-2939

Disclosure Date: September 06, 2022 (last updated October 08, 2023)
The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied through the 'author' parameter found in the ~/cerber-load.php file. In vulnerable versions, the plugin only blocks requests if the value supplied is numeric, making it possible for attackers to supply additional non-numeric characters to bypass the protection. The non-numeric characters are stripped and the user requested is displayed. This can be used by unauthenticated attackers to gather information about users that can targeted in further attacks.
Attacker Value
Unknown

CVE-2022-2538

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an attribute of a backend page, leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2021-25102

Disclosure Date: May 02, 2022 (last updated October 07, 2023)
The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Site Scripting issue. Exploitation of this issue requires the Login Page URL value to be known, which should be hard to guess, reducing the risk
Attacker Value
Unknown

CVE-2022-0429

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.
Attacker Value
Unknown

CVE-2021-24328

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well
Attacker Value
Unknown

CVE-2020-29171

Disclosure Date: February 10, 2021 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.
Attacker Value
Unknown

CVE-2015-9310

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
0
Attacker Value
Unknown

CVE-2016-10888

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
0
Attacker Value
Unknown

CVE-2016-10887

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
0