Weak configuration vulnerability in Solid Security – Password, Two Factor Authentication, and Brute Force Protection 9.0.0

The Solid Security plugin for WordPress is vulnerable to a security issue in all versions up to, and including, 9.0.0. This issue means that if someone has comments enabled on their website and they require registration for people to comment, then it is possible for unauthenticated attackers to discover the login page path and bypass the intended security mechanism. This could leave the website vulnerable to unwanted access.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.