iThemes Security

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in iThemes Security 3.6.3

    Fixed

    The Better WP Security plugin for WordPress has a security flaw in versions up to 3.6.3. This flaw makes it possible for attackers who have already logged into the system to insert malicious web scri...

    Read More
  • Input validation vulnerability in iThemes Security 5.3.5

    Fixed

    The iThemes Security plugin for WordPress is vulnerable to a type of attack called Cross-Site Scripting (XSS). Versions up to and including 5.3.4 of the plugin have a security flaw that does not prop...

    Read More
  • Input validation vulnerability in iThemes Security 3.2.4

    Fixed

    The Better WP Security plugin for WordPress had multiple security flaws allowing remote attackers to put malicious code on websites using the plugin. This code could allow attackers to access or modif...

    Read More
  • Input validation vulnerability in iThemes Security 3.4.4

    Fixed

    The iThemes Security plugin for WordPress is vulnerable to malicious code being injected into webpages. This vulnerability affects versions up to and including 3.4.3. Unauthenticated attackers can in...

    Read More
  • Input validation vulnerability in iThemes Security 4.6.13

    Fixed

    The iThemes Security plugin for WordPress is vulnerable to a type of malicious code, called Stored Cross-Site Scripting, in versions up to and including 4.6.12. This vulnerability allows attackers to...

    Read More
  • Input validation vulnerability in iThemes Security 6.9.0

    Fixed

    The iThemes Security plugin for WordPress

    Read More
  • Input validation vulnerability in iThemes Security 5.6.2

    Fixed

    The iThemes Security for WordPress was vulnerable to a type of attack called Stored Cross-Site Scripting. This was possible because of a lack of protection against malicious inputs and outputs in ver...

    Read More
  • Input validation vulnerability in iThemes Security 3.6.4

    Fixed

    The iThemes Security plugin for WordPress has a security vulnerability in versions before 3.6.4 that could allow attackers to insert malicious code into pages on a website. When a user accesses an in...

    Read More
  • Input validation vulnerability in iThemes Security 7.0.3

    Fixed

    The iThemes Security plugin for WordPress before version 7.0.3 had a security flaw that allowed someone with Admin privileges to perform an attack called SQL Injection on the logs page.

    Read More
  • Access violation vulnerability in iThemes Security 7.6.1

    Fixed

    Read More
  • Input validation vulnerability in iThemes Security 3.2.5

    Fixed

    The Better WP Security (iThemes) plugin for WordPress

    Read More
  • Access violation vulnerability in iThemes Security 5.3.1

    Fixed

    The iThemes Security plugin for WordPress is not secure in versions up to 5.3.0. This means that anyone can access the backup and log files created by the plugin, without needing to be authenticated ...

    Read More
  • Access violation vulnerability in iThemes Security 5.3.6

    Fixed

    The iThemes Security plugin for WordPress is not secure in versions up to 5.3.5. An attacker that is logged into the website can use this vulnerability to take administrative actions, such as creatin...

    Read More
  • Weak configuration vulnerability in iThemes Security 7.9.1

    Fixed

    by setting the ‘disable_wordpress_login_php’ option to true. It is possible to get around the login page that is hidden in iThemes Security (versions lower than 7.9.1) and iThemes Security Pro (v...

    Read More
  • Input validation vulnerability in iThemes Security 3.5.3

    Fixed

    The Better WP Security plugin for WordPress is vulnerable to a type of security problem called Stored Cross-Site Scripting. This vulnerability affects versions of the plugin up to and including versi...

    Read More
  • Information leakage vulnerability in iThemes Security 5.6.1

    Fixed

    The iThemes Security plugin for WordPress has a vulnerability in versions up to, and including 5.6.1, that could allow attackers to gain access to sensitive information. The vulnerability works by ca...

    Read More
  • Input validation vulnerability in iThemes Security 8.1.4

    Fixed

    The iThemes Security plugin for WordPress has a security issue in versions up to

    Read More