CVE-2023-52147: WordPress All-In-One Security (AIOS) plugin <= 5.2.4 - Secret Login Page Location Disclosure on Multisites vulnerability
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects All In One WP Security & Firewall: from n/a through 5.2.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52147?
CVE-2023-52147 has been assessed to have a medium severity level due to its potential for exposing sensitive information.
How do I fix CVE-2023-52147?
To remediate CVE-2023-52147, update the All In One WP Security & Firewall plugin to the latest version beyond 5.2.4.
Which versions of All In One WP Security & Firewall are affected by CVE-2023-52147?
CVE-2023-52147 affects All In One WP Security & Firewall versions from n/a to 5.2.4.
What is the nature of the vulnerability CVE-2023-52147?
CVE-2023-52147 involves the exposure of sensitive information due to improper access control list (ACL) enforcement.
Who is affected by CVE-2023-52147?
Users of the All In One WP Security & Firewall plugin up to version 5.2.4 on WordPress environments are affected by CVE-2023-52147.