WordPress Security Plugin Caught Logging Plaintext Passwords

Robert Reeve.
July 17, 2023

According to several reports, the All-In-One Security (AIOS) WordPress plugin has been logging plaintext passwords from user login attempts. The plugin, which is currently installed on more than one million Wordpress sites, was originally designed to prevent cyberattacks. Understandably, AIOS is now under heavy scrutiny for what many users call an unjustifiable breach of privacy, especially for a plugin that prides itself on security.

WordPress Security Plugin Caught Logging Plaintext Passwords.

Users identified the AIOS issue almost two weeks ago. Many began to complain about the problem on the plugin’s forums. In brief, the issue allowed any user with admin rights to access the login credentials of all other administrator users. Understandably, this has led to outrage among the AIOS community.

AIOS claims that the password-logging problem was the result of a bug. In response, the development team released an update, version 5.2.0, to address the issue and remove all logged passwords from their database. Although this change seems to have rectified the core problem, AIOS aren’t out of the woods yet. Many users report that version 5.2.0 is causing their websites to break. In addition, Wordpress statistics show us that hundreds of thousands of users are still using the vulnerable, outdated version of the plugin. Evidently, AIOS still has a long way to go to fully rectify their mistake.

The biggest question mark surrounding this whole situation is why AIOS is yet to step forward and recommend that all users change their passwords, especially if they utilize the same password for multiple sites. All in all, this is a worrying time for AIOS. Whether their reputation will recover from this event remains to be seen.


Robert Reeve

Robert is an experienced marketing professional with extensive experience working with brands to refine go-to-market plans, SEO campaigns, and content marketing strategies. A committed writer with a keen eye on the latest developments, Robert specialises in producing content across all things tech and marketing.

Read Next

15 Best New Fonts, July 2024

Welcome to our monthly roundup of the best fonts we’ve found online in the last four weeks. This month, there are fewer…

20 Best New Websites, July 2024

Welcome to July’s round up of websites to inspire you. This month’s collection ranges from the most stripped-back…

Top 7 WordPress Plugins for 2024: Enhance Your Site's Performance

WordPress is a hands-down favorite of website designers and developers. Renowned for its flexibility and ease of use,…

Exciting New Tools for Designers, July 2024

Welcome to this July’s collection of tools, gathered from around the web over the past month. We hope you’ll find…

3 Essential Design Trends, July 2024

Add some summer sizzle to your design projects with trendy website elements. Learn what's trending and how to use these…

15 Best New Fonts, June 2024

Welcome to our roundup of the best new fonts we’ve found online in the last month. This month, there are notably fewer…

20 Best New Websites, June 2024

Arranging content in an easily accessible way is the backbone of any user-friendly website. A good website will present…

Exciting New Tools for Designers, June 2024

In this month’s roundup of the best tools for web designers and developers, we’ll explore a range of new and noteworthy…

3 Essential Design Trends, June 2024

Summer is off to a fun start with some highly dramatic website design trends showing up in projects. Let's dive in!

15 Best New Fonts, May 2024

In this month’s edition, there are lots of historically-inspired typefaces, more of the growing trend for French…

How to Reduce The Carbon Footprint of Your Website

On average, a web page produces 4.61 grams of CO2 for every page view; for whole sites, that amounts to hundreds of KG…

20 Best New Websites, May 2024

Welcome to May’s compilation of the best sites on the web. This month we’re focused on color for younger humans,…