Description
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall is prone to multiple vulnerabilities, including security bypass and information disclosure vulnerabilities. An attacker may leverage these issues to perform otherwise restricted actions and subsequently bypass CAPTCHA answer validation or to obtain sensitive information that may help in launching further attacks. WordPress Plugin All-In-One Security (AIOS)-Security and Firewall version 4.1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.1.3 or latest
References
Related Vulnerabilities
WordPress Plugin Smart Forms-when you need more than just a contact form Security Bypass (2.6.84)
Mailman Other Vulnerability (CVE-2005-3573)
PHP Other Vulnerability (CVE-2005-0525)
WordPress Plugin WP Plugin Info Card Unspecified Vulnerability (2.3.6)
WordPress Plugin Connections Business Directory Unspecified Vulnerability (10.4.7)