4.8
CVSSv3

CVE-2023-0157

Published: 10/04/2023 Updated: 07/11/2023
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 0

Vulnerability Summary

The All-In-One Security (AIOS) WordPress plugin prior to 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this page.

Vulnerable Product Search on Vulmon Subscribe to Product

updraftplus all-in-one security

Vendor Advisories

Check Point Reference: CPAI-2023-1633 Date Published: 7 Apr 2024 Severity: Medium ...

Github Repositories

Repository for CVE-2023-0157 vulnerability.

CVE ID: CVE-2023-0157 Vulnerability Type: Directory Traversal Description: The All-In-One Security (AIOS) plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 514 This allows authenticated attackers with administrator-level permissions to read the contents of arbitrary files on the server Steps to reproduce: Just create a testpdf file