WordPress Security Plugin Caught Logging Plaintext Passwords

Robert Reeve.
July 17, 2023

According to several reports, the All-In-One Security (AIOS) WordPress plugin has been logging plaintext passwords from user login attempts. The plugin, which is currently installed on more than one million Wordpress sites, was originally designed to prevent cyberattacks. Understandably, AIOS is now under heavy scrutiny for what many users call an unjustifiable breach of privacy, especially for a plugin that prides itself on security.

WordPress Security Plugin Caught Logging Plaintext Passwords.

Users identified the AIOS issue almost two weeks ago. Many began to complain about the problem on the plugin’s forums. In brief, the issue allowed any user with admin rights to access the login credentials of all other administrator users. Understandably, this has led to outrage among the AIOS community.

AIOS claims that the password-logging problem was the result of a bug. In response, the development team released an update, version 5.2.0, to address the issue and remove all logged passwords from their database. Although this change seems to have rectified the core problem, AIOS aren’t out of the woods yet. Many users report that version 5.2.0 is causing their websites to break. In addition, Wordpress statistics show us that hundreds of thousands of users are still using the vulnerable, outdated version of the plugin. Evidently, AIOS still has a long way to go to fully rectify their mistake.

The biggest question mark surrounding this whole situation is why AIOS is yet to step forward and recommend that all users change their passwords, especially if they utilize the same password for multiple sites. All in all, this is a worrying time for AIOS. Whether their reputation will recover from this event remains to be seen.


Robert Reeve

Robert is an experienced marketing professional with extensive experience working with brands to refine go-to-market plans, SEO campaigns, and content marketing strategies. A committed writer with a keen eye on the latest developments, Robert specialises in producing content across all things tech and marketing.

Read Next

10 Best Web Design Trends of 2023

What website design techniques made the most impact in 2023? We've got a look back at the best trends of the year.

30 Free Xmas Graphics

We’ve reached that time of year when all marketing is on a singular theme: snow, presents, and turkey (or nut roast, if…

40 Best New Websites, 2023

What makes a website great? Is it the design, the functionality, the subject? Or is it specific design elements like…

30 Most Exciting New Tools for Designers, 2023

As we near the end of 2023, we wanted to take a look back over all the tools we collected over the past year, to pick…

3 Essential Design Trends, December 2023

While we love the holidays, too much of a seasonal theme can get overwhelming. Thankfully, these design trends strike a…

10 Easy Ways to Make Money as a Web Designer

When you’re a web designer, the logical way to make money is designing websites; you can apply for a job at an agency,…

The 10 Most Hated Fonts of All Time

Remember when Comic Sans wasn’t the butt of the jokes? Long for the days when we actually enjoyed using the Impact…

15 Best New Fonts, November 2023

2023 is almost over, and the new fonts are still coming thick and fast. This month, we’ve found some awesome variable…

Old School Web Techniques Best Forgotten

When the web first entered the public consciousness back in the 90s, it was primarily text-based with minimal design…

20 Best New Websites, November 2023

As the nights draw in for the Northern hemisphere, what better way to brighten your day than by soaking up some design…

30 Amazing Chrome Extensions for Designers and Developers

Searching for a tool to make cross-platform design a breeze? Desperate for an extension that helps you figure out the…

Exciting New Tools for Designers, November 2023

We’ve got a mix of handy image helpers, useful design assets, and clever productivity tools, amongst other treats. Some…