VYPR
Low severity3.7NVD Advisory· Published Jun 4, 2024· Updated Apr 15, 2026

CVE-2023-52147

CVE-2023-52147

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects All In One WP Security & Firewall: from n/a through 5.2.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

All In One WP Security & Firewall plugin up to 5.2.4 exposes sensitive information due to missing access controls, enabling unauthorized functionality access.

Vulnerability

The All In One WP Security & Firewall plugin for WordPress fails to properly constrain access to certain functionality, resulting in exposure of sensitive information to unauthorized actors. This issue affects versions from n/a through 5.2.4. The vulnerability is classified as an ACL bypass.

Exploitation

An attacker can exploit this vulnerability by directly accessing restricted endpoints or performing actions that should require higher privileges, without proper authentication or authorization checks. No special network position is required; the attacker only needs to be able to send HTTP requests to the WordPress site.

Impact

Successful exploitation allows an unauthorized actor to access sensitive information, such as configuration details or user data, that should be protected by access control lists. The impact is limited to information disclosure, with no direct code execution or privilege escalation.

Mitigation

A fix was introduced in version 5.2.5 of the plugin. Users should update to a version later than 5.2.4. The latest version available is 5.4.7 [1]. If unable to update, consider restricting access to the plugin's functionality via other security measures or disabling the plugin until a patched version can be applied.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.