What the vulnerability does
01Description
Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.
Explanation of Vulnerability in Simple Terms
The All-In-One Security plugin for WordPress versions up to 5.1.0 does not properly validate requests, allowing attackers to perform unauthorized actions on behalf of site administrators without their knowledge. An attacker can modify plugin settings, disable security features, or alter site configuration by tricking an admin into visiting a malicious page. This vulnerability requires no authentication but does require the admin to visit an attacker-controlled link.
What an attacker can do
Modify plugin settings or disable security features by tricking an admin into visiting a malicious page.
Potential impact on your site
Plugin settings could be changed or security features disabled without your knowledge or consent.
Conditions required to exploit
Site admin must visit an attacker-controlled page; no authentication required from the attacker.
Key dates
External resources
Related vulnerabilities