Connect with us

Hi, what are you looking for?



Popular WordPress Security Plugin Caught Logging Plaintext Passwords

The All-In-One Security (AIOS) WordPress plugin was found to be writing plaintext passwords to log files.

The All-In-One Security (AIOS) WordPress plugin was found to be logging plaintext passwords from login attempts.

Installed on more than one million WordPress sites, the security and firewall plugin was designed to prevent cyberattacks such as brute-force attempts, warn when the default admin username is used for login, prevent bot attacks, log user activity, and eliminate comment spam.

It was discovered that AIOS version 5.1.9 writes plaintext passwords from login attempts to the database, which essentially provides any privileged user with access to the login credentials of all other administrator users.

The issue was identified roughly two weeks ago, when users started complaining about the insecure design flaw on the plugin’s support forums.

Earlier this week, the Updraft team maintaining the plugin released AIOS version 5.2.0 to address the issue and remove the logged passwords from the database.

However, plugin users have been complaining about the update breaking sites and not removing the password logs. AIOS version 5.2.1 was released on Wednesday to address these issues, but some users claim sites are still broken.

According to Patchstack CEO Oliver Sild, however, the AIOS maintainers should have also warned users of the password logging, so that they could reset their credentials if the same combinations were used on multiple sites, as this creates an attack surface for threat actors.

“So far the developers haven’t even told the users to change all passwords. Due to the scale, we will 100% see hackers harvest the credentials from the logs of compromised sites that run (or has run) this plugin,” Sild tweeted.

Advertisement. Scroll to continue reading.

All-In-One Security (AIOS) users are advised to update their installations as soon as possible. Based on WordPress statistics, hundreds of thousands of websites are still running a vulnerable version of the plugin.

Related: 200,000 WordPress Sites Exposed to Attacks Exploiting Flaw in ‘Ultimate Member’ Plugin

Related: Critical WordPress Plugin Vulnerabilities Impact Thousands of Sites

Related: Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join us as we delve into the transformative potential of AI, predictive ChatGPT-like tools and automation to detect and defend against cyberattacks.


As cybersecurity breaches and incidents escalate, the cyber insurance ecosystem is undergoing rapid and transformational change.


Expert Insights

Related Content


Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...


A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...


Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.


Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.


The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.