The All-In-One Security (AIOS) WordPress security plugin was found to log plaintext passwords from user login attempts to the site’s database, putting account security at risk.
Roughly three weeks ago, a user reported that the AIOS v5.1.9 plugin was not only recording user login attempts to the aiowps_audit_log database table, used to track logins, logouts, and failed login events, but also recording the inputted password.
The issue was quickly fixed by Updraft, and an updated version of the plugin was released. However, the incident has raised concerns about the security of WordPress sites that use AIOS.
Bijay Pokharel
Bijay Pokharel is the Founder and Editor-in-Chief of Abijita.com and a freelance technology writer covering the tech industry since 2017. He specializes in cybersecurity, digital privacy, malware, vulnerabilities, and online safety, with a strong interest in internet protection and women’s online security. A dedicated tech enthusiast and continuous learner, Bijay approaches his professional work with clarity, rational thinking, and a calm, solution-oriented mindset.





