plugin

Better Wp Security Vulnerabilities

62 known security issues reported for the Better Wp Security WordPress plugin. Most recent disclosed Jun 21, 2024.

7 high 11 medium 1 low

Running Better Wp Security on your site? Check whether your installed version is affected.

Scan your site free

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.3.2

unknown

[en] Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n/a through 9.3.1.

Affected:
up to 9.3.2
Fixed in:
9.3.2
Disclosed:
Jun 21, 2024

CVE-2022-44593 on NVD →

Solid Security <= 9.3.1 - IP Address Spoofing to Denial of Service

medium

The Solid Security – Password, Two Factor Authentication, and Brute Force Protection plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 9.3.1 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to perform a denial of service attack...

CVSS:
5.3
Affected:
up to 9.3.1
Fixed in:
9.3.2
Disclosed:
Jun 20, 2024

CVE-2022-44593 on NVD →

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 8.1.5

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authentication, and Brute Force Protection.This issue affects Solid Security – Password, Two Factor Authentication, and Brute Force Protection: from n/a through 8.1.4.

Affected:
up to 8.1.5
Fixed in:
8.1.5
Disclosed:
Dec 29, 2023

CVE-2023-28786 on NVD →

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.0.1

unknown

Update the WordPress Better WP Security plugin to the latest available version (at least 9.0.1). Naveen Muthusamy discovered and reported this Sensitive Data Exposure vulnerability in WordPress Solid Security Plugin. This vulnerability has been fixed in version 9.0.1.

Affected:
up to 9.0.1
Fixed in:
9.0.1
Disclosed:
Nov 1, 2023

Solid Security Basic <= 9.0.0 - Unauthenticated Login Page Disclosure

medium

The Solid Security – Password, Two Factor Authentication, and Brute Force Protection plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 9.0.0. This is due to the plugin disclosing the login path when comments are enabled and registration is required. This makes it po...

CVSS:
5.3
Affected:
up to 9.0.0
Fixed in:
9.0.1
Disclosed:
Oct 31, 2023

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.0.1

unknown

The Solid Security – Password, Two Factor Authentication, and Brute Force Protection plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 9.0.0. This is due to the plugin disclosing the login path when comments are enabled and registration is required. This makes it po...

Affected:
up to 9.0.1
Fixed in:
9.0.1
Disclosed:
Oct 31, 2023

iThemes Security <= 8.1.4 - Open Redirection via redirect_to_https

medium

The iThemes Security plugin for WordPress is vulnerable to open redirection in versions up to, and including, 8.1.4. This is due to the use of wp_redirect instead of wp_safe_redirect in the redirect_to_https function. This makes it possible for unauthenticated attackers to arbitrarily redirect users via a forged reques...

CVSS:
4.7
Affected:
up to 8.1.4
Fixed in:
8.1.5
Disclosed:
Mar 27, 2023

CVE-2023-28786 on NVD →

iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass

medium

It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4

CVSS:
5.3
Affected:
up to 7.9.1
Fixed in:
7.9.1
Disclosed:
Apr 22, 2021

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.9.1

unknown

It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4

Affected:
up to 7.9.1
Fixed in:
7.9.1
Disclosed:
Apr 22, 2021

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.9.1

unknown

Hide Backend Bypass vulnerability discovered by Julio Potier (SecuPress) in WordPress iThemes Security plugin (versions <= 7.9.0).

Affected:
up to 7.9.1
Fixed in:
7.9.1
Disclosed:
Apr 21, 2021

iThemes Security <= 7.6.1 - Broken Password Mechanism

high

The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.

CVSS:
7.5
Affected:
up to 7.6.1
Fixed in:
7.7.0
Disclosed:
Jan 6, 2021

CVE-2020-36176 on NVD →

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.7.0

unknown

[en] The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.

Affected:
up to 7.7.0
Fixed in:
7.7.0
Disclosed:
Jan 6, 2021

CVE-2020-36176 on NVD →

iThemes Security <= 7.0.2 - Authenticated SQL Injection

high

The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.

CVSS:
7.2
Affected:
up to 7.0.3
Fixed in:
7.0.3
Disclosed:
Jun 25, 2018

CVE-2018-12636 on NVD →

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.0.3

unknown

[en] The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.

Affected:
up to 7.0.3
Fixed in:
7.0.3
Disclosed:
Jun 22, 2018

CVE-2018-12636 on NVD →

iThemes Security <= 6.9.0 - Cross-Site Scripting

high

The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.

CVSS:
7.5
Affected:
up to 6.9.0
Fixed in:
6.9.1
Disclosed:
Mar 5, 2018

CVE-2018-7433 on NVD →

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 6.9.1

unknown

[en] The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.

Affected:
up to 6.9.1
Fixed in:
6.9.1
Disclosed:
Mar 2, 2018

CVE-2018-7433 on NVD →

iThemes Security <= 5.6.1 - Stored Cross-Site Scripting

medium

The iThemes Security for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenev...

CVSS:
6.4
Affected:
up to 5.6.2
Fixed in:
5.6.2
Disclosed:
Oct 6, 2016

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2

unknown

The iThemes Security for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenev...

Affected:
up to 5.6.2
Fixed in:
5.6.2
Disclosed:
Oct 6, 2016

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 5.6.2
Fixed in:
5.6.2
Disclosed:
Oct 6, 2016

iThemes Security <= 5.6.1 - Sensitive Information Exposure via Diff Response

medium

The iThemes Security plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including 5.6.1, due to invalid username/password combinations returning different HTTP headers on response. This makes it possible for attackers to observe differences in responses to determine valid user...

CVSS:
5.3
Affected:
up to 5.6.1
Fixed in:
5.6.2
Disclosed:
Sep 27, 2016

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2

unknown

The iThemes Security plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including 5.6.1, due to invalid username/password combinations returning different HTTP headers on response. This makes it possible for attackers to observe differences in responses to determine valid user...

Affected:
up to 5.6.2
Fixed in:
5.6.2
Disclosed:
Sep 27, 2016

iThemes Security <= 5.3.5 - Missing Capabilities Check

high

The iThemes Security plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_itsec_file_change_warning_ajax function in versions up to, and including, 5.3.5. This makes it possible for authenticated attackers to perform administrative actions.

CVSS:
7.4
Affected:
up to 5.3.6
Fixed in:
5.3.6
Disclosed:
Apr 25, 2016

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.6

unknown

This plugin is prone to lack of capability check vulnerability. It allows anyone “fake click” on this button, hiding the changes to the administrator. Update the plugin.

Affected:
up to 5.3.6
Fixed in:
5.3.6
Disclosed:
Apr 25, 2016

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.6

unknown

The iThemes Security plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_itsec_file_change_warning_ajax function in versions up to, and including, 5.3.5. This makes it possible for authenticated attackers to perform administrative actions.

Affected:
up to 5.3.6
Fixed in:
5.3.6
Disclosed:
Apr 25, 2016

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.1

unknown

This plugin is prone to insecure backup and logfile generation vulnerability. Update the plugin.

Affected:
up to 5.3.1
Fixed in:
5.3.1
Disclosed:
Apr 22, 2016

iThemes Security < 5.3.1 - Insecure Backup/Logfile Generation

medium

The iThemes Security plugin for WordPress is vulnerable to insecure backup and logfile generation in versions up to, and including, 5.3.0. This is due to backup and logfiles being created in a world-readable directory. This makes it possible for unauthenticated attackers to view backup and log files.

CVSS:
5.3
Affected:
up to 5.3.1
Fixed in:
5.3.1
Disclosed:
Apr 21, 2016

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.1

unknown

The iThemes Security plugin for WordPress is vulnerable to insecure backup and logfile generation in versions up to, and including, 5.3.0. This is due to backup and logfiles being created in a world-readable directory. This makes it possible for unauthenticated attackers to view backup and log files.

Affected:
up to 5.3.1
Fixed in:
5.3.1
Disclosed:
Apr 21, 2016

iThemes Security < 5.3.5 - Authenticated Cross-Site Scripting

low

The iThemes Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in...

CVSS:
3.3
Affected:
up to 5.3.5
Fixed in:
5.3.5
Disclosed:
Apr 5, 2016

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.5

unknown

The iThemes Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in...

Affected:
up to 5.3.5
Fixed in:
5.3.5
Disclosed:
Apr 5, 2016

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.5

unknown

This plugin is prone to potential authenticated DOM cross site scripting vulnerability. Update the plugin.

Affected:
up to 5.3.5
Fixed in:
5.3.5
Disclosed:
Apr 5, 2016

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.6.13

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 4.6.13
Fixed in:
4.6.13
Disclosed:
Oct 18, 2015

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.4.4

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 3.4.4
Fixed in:
3.4.4
Disclosed:
May 15, 2015

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4

unknown

This plugin is prone to /wp-admin/admin-ajax.php license parameter stored XSS weakness. Upgrade the plugin.

Affected:
up to 3.6.4
Fixed in:
3.6.4
Disclosed:
May 15, 2015

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.6

unknown

This plugin is prone to inc/admin/content.php id_specialfile parameter stored cross site scripting vulnerability. Update the plugin.

Affected:
up to 3.5.6
Fixed in:
3.5.6
Disclosed:
May 15, 2015

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.0.0

unknown

This plugin is prone to online backup storage current_time function brute force disclosure vulnerability. Upgrade the plugin.

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
May 15, 2015

iThemes Security <= 4.6.12 - Stored Cross-Site Scripting

medium

The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.6.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a us...

CVSS:
6.5
Affected:
up to 4.6.13
Fixed in:
4.6.13
Disclosed:
Apr 14, 2015

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.6.13

unknown

The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.6.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a us...

Affected:
up to 4.6.13
Fixed in:
4.6.13
Disclosed:
Apr 14, 2015

iThemes Security < 3.6.4 - Stored Cross-Site Scripting

high

The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter in versions before 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

CVSS:
8.3
Affected:
up to 3.6.4
Fixed in:
3.6.4
Disclosed:
Aug 1, 2014

Better WP Security <= 3.5.3 - Stored Cross-Site Scripting

high

The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inc/secure.php' file in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping on logged data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

CVSS:
7.2
Affected:
up to 3.5.3
Fixed in:
3.5.4
Disclosed:
Aug 1, 2014

Better WP Security <= 3.6.3 - Stored Cross-Site Scripting

medium

The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will e...

CVSS:
6.4
Affected:
up to 3.6.3
Fixed in:
3.6.4
Disclosed:
Aug 1, 2014

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4

unknown

The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will e...

Affected:
up to 3.6.4
Fixed in:
3.6.4
Disclosed:
Aug 1, 2014

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4

unknown

The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter in versions before 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

Affected:
up to 3.6.4
Fixed in:
3.6.4
Disclosed:
Aug 1, 2014

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.4

unknown

The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inc/secure.php' file in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping on logged data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

Affected:
up to 3.5.4
Fixed in:
3.5.4
Disclosed:
Aug 1, 2014

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.4

unknown

Better WP Security plugins is prone to a stored XSS vulnerability that allow to steal cookies or gain privileged access to the affected site. Update the plugin to 3.5.4 version.

Affected:
up to 3.5.4
Fixed in:
3.5.4
Disclosed:
Aug 2, 2013

iThemes Security < 3.4.4 - Cross-Site Scripting

medium

The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execut...

CVSS:
6.5
Affected:
up to 3.4.4
Fixed in:
3.4.4
Disclosed:
Aug 20, 2012

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.4.4

unknown

The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execut...

Affected:
up to 3.4.4
Fixed in:
3.4.4
Disclosed:
Aug 20, 2012

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.2.5

unknown

[en] Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Aug 13, 2012

CVE-2012-4263 on NVD →

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.2.5

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Aug 13, 2012

CVE-2012-4264 on NVD →

iThemes Security < 3.2.5 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (iThemes) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.

CVSS:
7.2
Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
May 11, 2012

CVE-2012-4263 on NVD →

Better WP Security <= 3.2.4 - Multiple Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263.

CVSS:
6.1
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
May 11, 2012

CVE-2012-4264 on NVD →

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.6

unknown
Affected:
up to 3.5.6
Fixed in:
3.5.6

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.6.13

unknown

The iThemes Security (formerly Better WP Security) WordPress plugin was affected by security vulnerability.

Affected:
up to 4.6.13
Fixed in:
4.6.13

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.0.1

unknown

The plugin is vulnerable to protection mechanism bypass due to disclosing the login path when comments are enabled and registration is required. This makes it possible for unauthenticated attackers to discover the login page path and bypass the intended functionality of the security mechanism.

Affected:
up to 9.0.1
Fixed in:
9.0.1

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.4

unknown

The iThemes Security (formerly Better WP Security) WordPress plugin was affected by an inc/secure.php logevent Function URL H&amp;ling Stored XSS security vulnerability.

Affected:
up to 3.5.4
Fixed in:
3.5.4

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.4.4

unknown
Affected:
up to 3.4.4
Fixed in:
3.4.4

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4

unknown
Affected:
up to 3.6.4
Fixed in:
3.6.4

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.5

unknown

The iThemes Security (formerly Better WP Security) WordPress plugin was affected by a Potential Authenticated DOM Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 5.3.5
Fixed in:
5.3.5

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.9.1

unknown

Both the iThemes Security free and pro versions were affected. - Patched in Version (iThemes Security): 7.9.1 - Patched in Version (iThemes Security Pro): 6.8.4 The bug allowed attackers to bypass the &quot;Hide Backend&quot; feature, that, when enabled, hides the WordPress wp-login.php and wp-admin pages. Th...

Affected:
up to 7.9.1
Fixed in:
7.9.1

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2

unknown

The 404 detection module needs to be enabled.

Affected:
up to 5.6.2
Fixed in:
5.6.2

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.6

unknown

The iThemes Security (formerly Better WP Security) WordPress plugin was affected by a Lack of Capability Check security vulnerability.

Affected:
up to 5.3.6
Fixed in:
5.3.6

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.1

unknown

The iThemes Security (formerly Better WP Security) WordPress plugin was affected by an Insecure Backup/Logfile Generation security vulnerability.

Affected:
up to 5.3.1
Fixed in:
5.3.1

Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.0.0

unknown
Affected:
up to 4.0.0
Fixed in:
4.0.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database