4.9
CVSSv3

CVE-2023-0156

Published: 10/04/2023 Updated: 07/11/2023
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

The All-In-One Security (AIOS) WordPress plugin prior to 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to which the web server has access). The plugin only displays the last 50 lines of the file.

Vulnerable Product Search on Vulmon Subscribe to Product

updraftplus all-in-one security

Vendor Advisories

Check Point Reference: CPAI-2023-1631 Date Published: 7 Apr 2024 Severity: Medium ...

Github Repositories

Repository for CVE-2023-0156 vulnerability.

CVE ID: CVE-2023-0156 Vulnerability Type: Directory Traversal Description: The All-In-One Security (AIOS) plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 514 This allows authenticated attackers with administrator-level permissions to read the contents of arbitrary files on the server Steps to reproduce: POST /wp-admin/adminphp?pa