CVE-2015-9310
Description
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple SQL injection vulnerabilities in the All-in-One WP Security & Firewall plugin before 3.9.1 allow unauthenticated attackers to execute arbitrary SQL queries.
Vulnerability
The All-in-One WP Security & Firewall plugin for WordPress versions before 3.9.1 contains multiple SQL injection vulnerabilities [1]. The issues exist in various plugin components that fail to properly sanitize user-supplied input before using it in SQL queries. The plugin is widely used for login security, firewall, and file scanning features.
Exploitation
An attacker can exploit these vulnerabilities without authentication by sending crafted HTTP requests to the WordPress site. The attacker does not need any special privileges or user interaction. The SQL injection can be triggered through multiple parameters in the plugin's functionality.
Impact
Successful exploitation allows an attacker to execute arbitrary SQL commands against the WordPress database. This can lead to extraction of sensitive data such as user credentials, session tokens, and other stored information. The attacker may also be able to modify or delete database content, potentially leading to full site compromise.
Mitigation
The vulnerability is fixed in version 3.9.1 of the plugin [1]. Users should update to the latest version (currently 5.4.7) to ensure protection. No workarounds are documented. The plugin is actively maintained and updated.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- WordPress/all-in-one-wp-security-and-firewalldescription
- Range: <3.9.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wordpress.org/plugins/all-in-one-wp-security-and-firewall/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.