What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects All In One WP Security & Firewall: from n/a through 5.2.4.
Explanation of Vulnerability in Simple Terms
02Summary
All In One WP Security & Firewall versions up to 5.2.4 expose sensitive information through improper access controls. An unauthenticated attacker can retrieve limited confidential data by exploiting network-accessible endpoints. The vulnerability requires specific conditions to trigger and has low confidentiality impact. Update to a version newer than 5.2.4 to remediate.
What an attacker can do
03Attacker Capabilities
Read limited sensitive information from the plugin without authentication.
Potential impact on your site
04Site Impact
Sensitive data may be exposed to unauthenticated visitors; update the plugin to patch the information disclosure.
Conditions required to exploit
05Prerequisites
Network access to the WordPress site; specific conditions must be met to trigger the vulnerability.
Key dates
06Disclosure timeline
June 4, 2024
CVE published
April 28, 2026
Record updated