Description
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall is prone to multiple vulnerabilities, including security bypass and information disclosure vulnerabilities. An attacker may leverage these issues to perform otherwise restricted actions and subsequently bypass CAPTCHA answer validation or to obtain sensitive information that may help in launching further attacks. WordPress Plugin All-In-One Security (AIOS)-Security and Firewall version 4.1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.1.3 or latest
References
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-5406)
Internet Information Services Other Vulnerability (CVE-2000-0114)
MediaWiki Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2021-36125)
WordPress Plugin WP Editor Multiple Vulnerabilities (1.2.5.3)