CVE-2026-96825: WordPress All In One WP Security & Firewall plugin <= 5.4.8 - Bypass Vulnerability vulnerability
Published Sep 30, 2026
·Updated
Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.
Affected Software
1 affected component
Tips And Tricks Hq All In One WP Security & Firewall<=5.4.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
All In One WP Security & Firewallto a version that resolves this vulnerability.Fixed in 5.4.9
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The vulnerability requires low-level authenticated access, as indicated by the PR:L vector. A subscriber-level account is specifically identified in the available information.
2
Can this be exploited remotely without user interaction?
The vector indicates network-based attack access and no user interaction requirement. Exploitation complexity is high, however.
3
What is the potential impact if exploitation succeeds?
Successful exploitation may result in limited confidentiality and integrity impact. No availability impact is indicated.