CVE-2016-10888: Tipsandtricks-Hq All In One Wp Security & Firewall

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.

Affected products

  • Tipsandtricks-Hq All In One Wp Security & Firewall: before 4.0.7 (fixed in 4.0.7)

Published 2019-08-14. Last modified 2026-06-17.