The All-In-One Security (AIOS) WordPress security plugin was found to log plaintext passwords from user login attempts to the site’s database, putting account security at risk.
Roughly three weeks ago, a user reported that the AIOS v5.1.9 plugin was not only recording user login attempts to the aiowps_audit_log database table, used to track logins, logouts, and failed login events, but also recording the inputted password.
The issue was quickly fixed by Updraft, and an updated version of the plugin was released. However, the incident has raised concerns about the security of WordPress sites that use AIOS.
Bijay Pokharel
Bijay Pokharel is the Founder and Editor-in-Chief of Abijita, an independent technology and cybersecurity news publication established in 2017. A specialist in cybersecurity journalism, Bijay covers vulnerability research, malware analysis, enterprise data breaches, digital privacy, and emerging technologies. His work translates complex technical threats into precise, accessible, and actionable intelligence for security professionals and general readers alike. His reporting and investigative coverage are routinely cited and republished across leading technology and security media.



