Vulnerabilities > Updraftplus > ALL IN ONE Security > 5.2.2

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-1037 Cross-site Scripting vulnerability in Updraftplus All-In-One Security
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping.
network
low complexity
updraftplus CWE-79
6.1