{"id":1372,"date":"2023-04-26T11:11:08","date_gmt":"2023-04-26T11:11:08","guid":{"rendered":"https:\/\/aspentheme.com\/?p=1372"},"modified":"2023-04-26T11:11:08","modified_gmt":"2023-04-26T11:11:08","slug":"two-vulnerabilities-found-in-popular-wordpress-security-plugin","status":"publish","type":"post","link":"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/","title":{"rendered":"Two Vulnerabilities Found in Popular WordPress Security Plugin"},"content":{"rendered":"\n

The All-In-One Security (AIOS) WordPress plugin, a security tool created by the publishers of UpdraftPlus, has been found to have two vulnerabilities. These security flaws may potentially allow malicious uploads, cross-site scripting, and unauthorized access to file contents.<\/p>\n\n\n\n

AIOS offers various security features, such as login protection, plagiarism prevention, hotlink blocking, spam comment filtering, and a firewall against hacking attempts. With over a million installations, it is a widely-used WordPress plugin.<\/p>\n\n\n\n

Recently, the US National Vulnerability Database (NVD) issued warnings about two vulnerabilities in the plugin:<\/p>\n\n\n\n

Data Sanitization Failure: The first issue is a failure to remove sensitive data from log files. This basic security measure, called “escaping data,” prevents unwanted data like malicious HTML or script tags from appearing in the output. The NVD states that an attacker with admin access can plant false log files with harmful JavaScript code, which will execute when an administrator visits the plugin admin page.<\/p>\n\n\n\n

Path Traversal Vulnerability: The second issue allows an attacker to exploit a security weakness and access files that should be inaccessible. By manipulating file references with “..\/” sequences or using absolute file paths, it’s possible to access sensitive files on the system. The NVD explains that an attacker with admin access can view the contents of any file on the server and list directories.<\/p>\n\n\n\n

Although both vulnerabilities require admin-level credentials to be exploited, it is concerning that a security plugin has these preventable issues.<\/p>\n\n\n\n

AIOS has released a patch (version 5.1.6) to address these vulnerabilities. Users should consider updating to at least version 5.1.6 or the latest version, 5.1.7, which fixes a crash related to the firewall setup.<\/p>\n","protected":false},"excerpt":{"rendered":"

The All-In-One Security (AIOS) WordPress plugin, a security tool created by the publishers of UpdraftPlus, has been found to have two vulnerabilities. These security flaws may potentially allow malicious uploads, cross-site scripting, and unauthorized access … Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":1374,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[14],"tags":[],"ppma_author":[9],"yoast_head":"\nTwo Vulnerabilities Found in Popular WordPress Security Plugin - AspenTheme<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Two Vulnerabilities Found in Popular WordPress Security Plugin - AspenTheme\" \/>\n<meta property=\"og:description\" content=\"The All-In-One Security (AIOS) WordPress plugin, a security tool created by the publishers of UpdraftPlus, has been found to have two vulnerabilities. These security flaws may potentially allow malicious uploads, cross-site scripting, and unauthorized access ... Read more\" \/>\n<meta property=\"og:url\" content=\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/\" \/>\n<meta property=\"og:site_name\" content=\"AspenTheme\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-26T11:11:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/aios-wordpress-vulnerability-643522d348cd8-sej.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"840\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Aspen Team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Aspen Team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/aspentheme.com\/#\/schema\/person\/15743c7b17320042c19b9faaecc0e4a5\"},\"headline\":\"Two Vulnerabilities Found in Popular WordPress Security Plugin\",\"datePublished\":\"2023-04-26T11:11:08+00:00\",\"dateModified\":\"2023-04-26T11:11:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/\"},\"wordCount\":275,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/aspentheme.com\/#organization\"},\"articleSection\":[\"Wordpress\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/\",\"url\":\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/\",\"name\":\"Two Vulnerabilities Found in Popular WordPress Security Plugin - AspenTheme\",\"isPartOf\":{\"@id\":\"https:\/\/aspentheme.com\/#website\"},\"datePublished\":\"2023-04-26T11:11:08+00:00\",\"dateModified\":\"2023-04-26T11:11:08+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/aspentheme.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wordpress\",\"item\":\"https:\/\/aspentheme.com\/category\/wordpress\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Two Vulnerabilities Found in Popular WordPress Security Plugin\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/aspentheme.com\/#website\",\"url\":\"https:\/\/aspentheme.com\/\",\"name\":\"AspenTheme\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/aspentheme.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/aspentheme.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/aspentheme.com\/#organization\",\"name\":\"AspenTheme\",\"url\":\"https:\/\/aspentheme.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/aspentheme.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/favicon.svg\",\"contentUrl\":\"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/favicon.svg\",\"width\":500,\"height\":500,\"caption\":\"AspenTheme\"},\"image\":{\"@id\":\"https:\/\/aspentheme.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/aspentheme.com\/#\/schema\/person\/15743c7b17320042c19b9faaecc0e4a5\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/aspentheme.com\/#\/schema\/person\/image\/e728e94e734579eb8c349cc71181e0d3\",\"url\":\"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/favicon.svg\",\"contentUrl\":\"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/favicon.svg\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/aspentheme.com\"],\"url\":\"https:\/\/aspentheme.com\/author\/aspenthemecom\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Two Vulnerabilities Found in Popular WordPress Security Plugin - AspenTheme","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/","og_locale":"en_US","og_type":"article","og_title":"Two Vulnerabilities Found in Popular WordPress Security Plugin - AspenTheme","og_description":"The All-In-One Security (AIOS) WordPress plugin, a security tool created by the publishers of UpdraftPlus, has been found to have two vulnerabilities. These security flaws may potentially allow malicious uploads, cross-site scripting, and unauthorized access ... Read more","og_url":"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/","og_site_name":"AspenTheme","article_published_time":"2023-04-26T11:11:08+00:00","og_image":[{"width":1600,"height":840,"url":"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/aios-wordpress-vulnerability-643522d348cd8-sej.jpg","type":"image\/jpeg"}],"author":"Aspen Team","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Aspen Team","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/#article","isPartOf":{"@id":"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/"},"author":{"name":"admin","@id":"https:\/\/aspentheme.com\/#\/schema\/person\/15743c7b17320042c19b9faaecc0e4a5"},"headline":"Two Vulnerabilities Found in Popular WordPress Security Plugin","datePublished":"2023-04-26T11:11:08+00:00","dateModified":"2023-04-26T11:11:08+00:00","mainEntityOfPage":{"@id":"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/"},"wordCount":275,"commentCount":0,"publisher":{"@id":"https:\/\/aspentheme.com\/#organization"},"articleSection":["Wordpress"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/","url":"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/","name":"Two Vulnerabilities Found in Popular WordPress Security Plugin - AspenTheme","isPartOf":{"@id":"https:\/\/aspentheme.com\/#website"},"datePublished":"2023-04-26T11:11:08+00:00","dateModified":"2023-04-26T11:11:08+00:00","breadcrumb":{"@id":"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/aspentheme.com\/wordpress\/two-vulnerabilities-found-in-popular-wordpress-security-plugin\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/aspentheme.com\/"},{"@type":"ListItem","position":2,"name":"Wordpress","item":"https:\/\/aspentheme.com\/category\/wordpress\/"},{"@type":"ListItem","position":3,"name":"Two Vulnerabilities Found in Popular WordPress Security Plugin"}]},{"@type":"WebSite","@id":"https:\/\/aspentheme.com\/#website","url":"https:\/\/aspentheme.com\/","name":"AspenTheme","description":"","publisher":{"@id":"https:\/\/aspentheme.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/aspentheme.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/aspentheme.com\/#organization","name":"AspenTheme","url":"https:\/\/aspentheme.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/aspentheme.com\/#\/schema\/logo\/image\/","url":"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/favicon.svg","contentUrl":"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/favicon.svg","width":500,"height":500,"caption":"AspenTheme"},"image":{"@id":"https:\/\/aspentheme.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/aspentheme.com\/#\/schema\/person\/15743c7b17320042c19b9faaecc0e4a5","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/aspentheme.com\/#\/schema\/person\/image\/e728e94e734579eb8c349cc71181e0d3","url":"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/favicon.svg","contentUrl":"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/favicon.svg","caption":"admin"},"sameAs":["https:\/\/aspentheme.com"],"url":"https:\/\/aspentheme.com\/author\/aspenthemecom\/"}]}},"authors":[{"term_id":9,"user_id":1,"is_guest":0,"slug":"aspenthemecom","display_name":"Aspen Team","avatar_url":{"url":"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/favicon.svg","url2x":"https:\/\/aspentheme.com\/wp-content\/uploads\/2023\/04\/favicon.svg"},"user_url":"https:\/\/aspentheme.com","last_name":"Team","first_name":"Aspen","description":"We are the admins and main contributors to the site."}],"_links":{"self":[{"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/posts\/1372"}],"collection":[{"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/comments?post=1372"}],"version-history":[{"count":1,"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/posts\/1372\/revisions"}],"predecessor-version":[{"id":1373,"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/posts\/1372\/revisions\/1373"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/media\/1374"}],"wp:attachment":[{"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/media?parent=1372"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/categories?post=1372"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/tags?post=1372"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/aspentheme.com\/wp-json\/wp\/v2\/ppma_author?post=1372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}