CVE-2022-4097

MEDIUM

All-In-One Security (AIOS) <5.0.8 - Open Redirect

Title source: llm
STIX 2.1

Description

The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, brute force protection, and more).

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/15819d33-7497-4f7d-bbb8-b3ab147806c4

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 40.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
updraftplus/all-in-one_security < 5.0.8
Published Dec 12, 2022
Tracked Since Feb 18, 2026