Input validation vulnerability in All-In-One Security (AIOS) – Security and Firewall 5.2.5

The All-In-One Security (AIOS) plugin, used for security and firewall purposes on WordPress, has a vulnerability that allows hackers to inject harmful web scripts through the ‘tab’ parameter. This can happen in all versions up to and including 5.2.5 because the plugin does not properly filter and protect user input. This means that attackers who are not logged in can cause harm by tricking a user into clicking on a link.

Detected in:

All-In-One Security (AIOS) – Security and Firewall fixed vulnerable versions: >= * <= 5.2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.