Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0156


The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to which the web server has access). The plugin only displays the last 50 lines of the file.


Published

2023-04-10T14:15:08.100

Last Modified

2025-02-11T15:15:15.740

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application updraftplus all-in-one_security < 5.1.5 Yes

References