WordPress Plugin Vulnerabilities

All In One WP Security & Firewall <= 4.4.1 - Open Redirect & Hidden Login Page Exposure

Description

The All In One WP Security & Firewall plugin suffers from open redirect and exposure of the actual URL of the "hidden login page" feature.

Edit (WPScanTeam)
October 3rd, 2019 - Email sent to dev via https://wpsolutions-hq.com/contact/
October 8th - Dev ACK & investigating it
October 8th - v4.4.2 released, fixing the issues (confirmed by researcher)

Proof of Concept

Affects Plugins

Classification

Type
REDIRECT
OWASP top 10
CWE

Miscellaneous

Timeline

Publicly Published
2019-10-08 (about 6 years ago)
Added
2019-10-08 (about 6 years ago)
Last Updated
2019-10-08 (about 6 years ago)

Other