CVE-2020-29171: Tipsandtricks-Hq Wp Security & Firewall

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.

Affected products

Published 2021-02-10. Last modified 2026-06-17.