WordPress News
All-In-One Security (AIOS) 5.4.9 Released
What’s new in All-In-One Security (AIOS) 5.4.9
Released: 5/Jun/2026
Active installations: 1,000,000
Tested up to WordPress 7.0.2
Requires PHP 5.6
Changelog
- TWEAK: Added a filter that validates POST requests containing UDRPC messages
- TWEAK: Update the internal common libs package to latest version
Previous releases
5.4.8 — 2/Jun/2026
- SECURITY: Escaped debug log messages before rendering them in the admin area to prevent a stored XSS vulnerability. Thanks to Dmitrii Ignatyev for disclosing this defect. (This issue required both the debug logging feature and the “Disallow unauthorized REST API requests” setting to be enabled. Under those conditions, an attacker could inject malicious scripts into the debug logs via specially crafted requests, which could execute when viewed by an administrator on the AIOS debug logs page).
- FEATURE: Add notification method to reporting class to handle mails
- FEATURE: Added bulk actions to audit log table for blacklisting IPs
- FIX: Fixed minor bug when setting up TFA with the Onboarding wizard where correct codes are rejected if they are entered more than once.
- FIX: Log out button/link not working immediately after enabling the rename login feature
5.4.7 — 27/Apr/2026
- FEATURE: Added a dashboard widget for the top 5 failed login attempts by IP & username and a chart for the number of failed logins over the last 7 days.
- FIX: WordPress 7.0 admin UI compatibility issues resolved.
- FIX: Blacklist IP and User Agent firewalls could still be active when turned off.
- FIX: Table sorting indicators not being shown on WordPress version 6.3 and above.
- FIX: “Set up IP address detection settings” button not working in setup notice.