CVE-2023-52147 LOW

CVE-2023-52147: WordPress All-In-One Security (AIOS) plugin <= 5.2.4 - Secret Login Page Location Disclosure on Multisites vulnerability

Vendor All In One Wp Security & Firewall Team
Product All In One WP Security & Firewall
Weakness CWE-200 · Info exposure
Published June 4, 2024
Last update April 28, 2026

CVSS base score

3.7/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects All In One WP Security & Firewall: from n/a through 5.2.4.

Explanation of Vulnerability in Simple Terms

02Summary

All In One WP Security & Firewall versions up to 5.2.4 expose sensitive information through improper access controls. An unauthenticated attacker can retrieve limited confidential data by exploiting network-accessible endpoints. The vulnerability requires specific conditions to trigger and has low confidentiality impact. Update to a version newer than 5.2.4 to remediate.

What an attacker can do

03Attacker Capabilities

Read limited sensitive information from the plugin without authentication.

Potential impact on your site

04Site Impact

Sensitive data may be exposed to unauthenticated visitors; update the plugin to patch the information disclosure.

Conditions required to exploit

05Prerequisites

Network access to the WordPress site; specific conditions must be met to trigger the vulnerability.

Key dates

06Disclosure timeline

June 4, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE