Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-0157

The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.396
EPSS Ranking 97.2%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2023-0157


Contact Us

Shodan ® - All rights reserved