This WordPress plugin with over a million installs had a major security flaw

WordPress logo
(Image credit: WordPress)

A popular plugin for the WordPress website builder with more than a million users was caught storing user passwords in plaintext, available for website admins to read whenever they pleased.

A report on Ars Technica found the plugin in question, called All-In-One-Security (AIOS), was installed on at least a million websites. 

Earlier this week, its developers confirmed the flaw, saying it was a bug in the plugin’s version 5.1.9. Now, there is version 5.2.0, and users are advised to update their plugin immediately. Besides stopping the plugin from saving user passwords in plaintext, the patch also “delets the problematic data from the database,” the developers said. 

Rogue admins

Speaking to Ars Technica via email, a representative of the company tried to play down the flaw, saying the passwords were only available for administrators. And when an admin goes rogue (or has their account stolen/compromised), that’s as big of an issue as they come: “gaining anything from this defect requires being logged in with the highest-level administrative privileges, or equivalent. i.e. It can be exploited by a rogue admin who can already do such things because he's an admin,” the email reads.

But no one should ever have access to anyone’s password. At the end of the day, hackers can try and use these passwords on other platforms and services, too. Many users go for the same login credentials across numerous services, and breaching one might mean breaching many.

Still, AIOS’ developers apologizerd for the mistake, and gave a few pointers on what admins should do next. That includes updating all WordPress plugins, enabling multi-factor authentication (MFA) if possible, and changing passwords regularly.

The latter, Ars Technica reminds, is no longer considered industry-standard, as some research determined that regular password changing can do more harm than good.

Via: Ars Technica

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack
WordPress
Another top WordPress plugin found carrying critical security flaws
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
WordPress
WordPress users beware - these popular theme plugins have some major security issues
Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space