← العودة للجدول
CVE-2026-8438
CVE-2026-8438 — The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is
📅 2026-06-05
🟠 High 🔥 No NVD Exploit iOS CVSS 7.2

📋 الوصف الكامل

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanitization in the get_rest_route() function and missing output escaping in the column_default() method of the debug log list table. When the 'Disable REST API for non-logged in users' feature

💻 الأنظمة المتأثرة

Apple iOS | WordPress

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-8438

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v5.4.7

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←