WordPress Plugin Vulnerabilities
All In One WP Security & Firewall <= 4.4.1 - Open Redirect & Hidden Login Page Exposure
Description
The All In One WP Security & Firewall plugin suffers from open redirect and exposure of the actual URL of the "hidden login page" feature.
Edit (WPScanTeam)
October 3rd, 2019 - Email sent to dev via https://wpsolutions-hq.com/contact/
October 8th - Dev ACK & investigating it
October 8th - v4.4.2 released, fixing the issues (confirmed by researcher)
Proof of Concept
Affects Plugins
Classification
Type
REDIRECT
OWASP top 10
CWE
Miscellaneous
Verified
No
WPVDB ID
Timeline
Publicly Published
2019-10-08 (about 6 years ago)
Added
2019-10-08 (about 6 years ago)
Last Updated
2019-10-08 (about 6 years ago)