VYPR
Unrated severityNVD Advisory· Published Aug 14, 2019· Updated Aug 6, 2024

CVE-2015-9310

CVE-2015-9310

Description

The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple SQL injection vulnerabilities in the All-in-One WP Security & Firewall plugin before 3.9.1 allow unauthenticated attackers to execute arbitrary SQL queries.

Vulnerability

The All-in-One WP Security & Firewall plugin for WordPress versions before 3.9.1 contains multiple SQL injection vulnerabilities [1]. The issues exist in various plugin components that fail to properly sanitize user-supplied input before using it in SQL queries. The plugin is widely used for login security, firewall, and file scanning features.

Exploitation

An attacker can exploit these vulnerabilities without authentication by sending crafted HTTP requests to the WordPress site. The attacker does not need any special privileges or user interaction. The SQL injection can be triggered through multiple parameters in the plugin's functionality.

Impact

Successful exploitation allows an attacker to execute arbitrary SQL commands against the WordPress database. This can lead to extraction of sensitive data such as user credentials, session tokens, and other stored information. The attacker may also be able to modify or delete database content, potentially leading to full site compromise.

Mitigation

The vulnerability is fixed in version 3.9.1 of the plugin [1]. Users should update to the latest version (currently 5.4.7) to ensure protection. No workarounds are documented. The plugin is actively maintained and updated.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.