Access violation vulnerability in iThemes Security 5.3.1

The iThemes Security plugin for WordPress is not secure in versions up to 5.3.0. This means that anyone can access the backup and log files created by the plugin, without needing to be authenticated or having any specific permission. These backup and log files should remain private.

Detected in:

iThemes Security fixed vulnerable versions: >= * < 5.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.