Description
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin All-In-One Security (AIOS)-Security and Firewall version 5.1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.3 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:CC05F760-983D-4DC1-AFBB-6B4965AA8ABE
https://plugins.svn.wordpress.org/all-in-one-wp-security-and-firewall/trunk/readme.txt
Related Vulnerabilities
WordPress Multiple Cross-Site Scripting Vulnerabilities (1.2 - 1.2.1)
Caddy Web Server Authentication Bypass by Spoofing Vulnerability (CVE-2023-50463)
WordPress Plugin Amelia-Events & Appointments Booking Calendar Cross-Site Scripting (1.0.46)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20099)