Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.3.2
unknown
[en] Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n/a through 9.3.1.
- Affected:
- up to 9.3.2
- Fixed in:
- 9.3.2
- Disclosed:
- Jun 21, 2024
CVE-2022-44593 on NVD →
Solid Security <= 9.3.1 - IP Address Spoofing to Denial of Service
medium
The Solid Security – Password, Two Factor Authentication, and Brute Force Protection plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 9.3.1 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to perform a denial of service attack...
- CVSS:
- 5.3
- Affected:
- up to 9.3.1
- Fixed in:
- 9.3.2
- Disclosed:
- Jun 20, 2024
CVE-2022-44593 on NVD →
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 8.1.5
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authentication, and Brute Force Protection.This issue affects Solid Security – Password, Two Factor Authentication, and Brute Force Protection: from n/a through 8.1.4.
- Affected:
- up to 8.1.5
- Fixed in:
- 8.1.5
- Disclosed:
- Dec 29, 2023
CVE-2023-28786 on NVD →
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.0.1
unknown
Update the WordPress Better WP Security plugin to the latest available version (at least 9.0.1).
Naveen Muthusamy discovered and reported this Sensitive Data Exposure vulnerability in WordPress Solid Security Plugin. This vulnerability has been fixed in version 9.0.1.
- Affected:
- up to 9.0.1
- Fixed in:
- 9.0.1
- Disclosed:
- Nov 1, 2023
Solid Security Basic <= 9.0.0 - Unauthenticated Login Page Disclosure
medium
The Solid Security – Password, Two Factor Authentication, and Brute Force Protection plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 9.0.0. This is due to the plugin disclosing the login path when comments are enabled and registration is required. This makes it po...
- CVSS:
- 5.3
- Affected:
- up to 9.0.0
- Fixed in:
- 9.0.1
- Disclosed:
- Oct 31, 2023
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.0.1
unknown
The Solid Security – Password, Two Factor Authentication, and Brute Force Protection plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 9.0.0. This is due to the plugin disclosing the login path when comments are enabled and registration is required. This makes it po...
- Affected:
- up to 9.0.1
- Fixed in:
- 9.0.1
- Disclosed:
- Oct 31, 2023
iThemes Security <= 8.1.4 - Open Redirection via redirect_to_https
medium
The iThemes Security plugin for WordPress is vulnerable to open redirection in versions up to, and including, 8.1.4. This is due to the use of wp_redirect instead of wp_safe_redirect in the redirect_to_https function. This makes it possible for unauthenticated attackers to arbitrarily redirect users via a forged reques...
- CVSS:
- 4.7
- Affected:
- up to 8.1.4
- Fixed in:
- 8.1.5
- Disclosed:
- Mar 27, 2023
CVE-2023-28786 on NVD →
iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass
medium
It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4
- CVSS:
- 5.3
- Affected:
- up to 7.9.1
- Fixed in:
- 7.9.1
- Disclosed:
- Apr 22, 2021
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.9.1
unknown
It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4
- Affected:
- up to 7.9.1
- Fixed in:
- 7.9.1
- Disclosed:
- Apr 22, 2021
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.9.1
unknown
Hide Backend Bypass vulnerability discovered by Julio Potier (SecuPress) in WordPress iThemes Security plugin (versions <= 7.9.0).
- Affected:
- up to 7.9.1
- Fixed in:
- 7.9.1
- Disclosed:
- Apr 21, 2021
iThemes Security <= 7.6.1 - Broken Password Mechanism
high
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.
- CVSS:
- 7.5
- Affected:
- up to 7.6.1
- Fixed in:
- 7.7.0
- Disclosed:
- Jan 6, 2021
CVE-2020-36176 on NVD →
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.7.0
unknown
[en] The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.
- Affected:
- up to 7.7.0
- Fixed in:
- 7.7.0
- Disclosed:
- Jan 6, 2021
CVE-2020-36176 on NVD →
iThemes Security <= 7.0.2 - Authenticated SQL Injection
high
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
- CVSS:
- 7.2
- Affected:
- up to 7.0.3
- Fixed in:
- 7.0.3
- Disclosed:
- Jun 25, 2018
CVE-2018-12636 on NVD →
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.0.3
unknown
[en] The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
- Affected:
- up to 7.0.3
- Fixed in:
- 7.0.3
- Disclosed:
- Jun 22, 2018
CVE-2018-12636 on NVD →
iThemes Security <= 6.9.0 - Cross-Site Scripting
high
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
- CVSS:
- 7.5
- Affected:
- up to 6.9.0
- Fixed in:
- 6.9.1
- Disclosed:
- Mar 5, 2018
CVE-2018-7433 on NVD →
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 6.9.1
unknown
[en] The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
- Affected:
- up to 6.9.1
- Fixed in:
- 6.9.1
- Disclosed:
- Mar 2, 2018
CVE-2018-7433 on NVD →
iThemes Security <= 5.6.1 - Stored Cross-Site Scripting
medium
The iThemes Security for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenev...
- CVSS:
- 6.4
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.2
- Disclosed:
- Oct 6, 2016
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2
unknown
The iThemes Security for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenev...
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.2
- Disclosed:
- Oct 6, 2016
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.2
- Disclosed:
- Oct 6, 2016
iThemes Security <= 5.6.1 - Sensitive Information Exposure via Diff Response
medium
The iThemes Security plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including 5.6.1, due to invalid username/password combinations returning different HTTP headers on response. This makes it possible for attackers to observe differences in responses to determine valid user...
- CVSS:
- 5.3
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.2
- Disclosed:
- Sep 27, 2016
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2
unknown
The iThemes Security plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including 5.6.1, due to invalid username/password combinations returning different HTTP headers on response. This makes it possible for attackers to observe differences in responses to determine valid user...
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.2
- Disclosed:
- Sep 27, 2016
iThemes Security <= 5.3.5 - Missing Capabilities Check
high
The iThemes Security plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_itsec_file_change_warning_ajax function in versions up to, and including, 5.3.5. This makes it possible for authenticated attackers to perform administrative actions.
- CVSS:
- 7.4
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
- Disclosed:
- Apr 25, 2016
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.6
unknown
This plugin is prone to lack of capability check vulnerability. It allows anyone “fake click” on this button, hiding the changes to the administrator.
Update the plugin.
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
- Disclosed:
- Apr 25, 2016
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.6
unknown
The iThemes Security plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_itsec_file_change_warning_ajax function in versions up to, and including, 5.3.5. This makes it possible for authenticated attackers to perform administrative actions.
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
- Disclosed:
- Apr 25, 2016
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.1
unknown
This plugin is prone to insecure backup and logfile generation vulnerability.
Update the plugin.
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.1
- Disclosed:
- Apr 22, 2016
iThemes Security < 5.3.1 - Insecure Backup/Logfile Generation
medium
The iThemes Security plugin for WordPress is vulnerable to insecure backup and logfile generation in versions up to, and including, 5.3.0. This is due to backup and logfiles being created in a world-readable directory. This makes it possible for unauthenticated attackers to view backup and log files.
- CVSS:
- 5.3
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.1
- Disclosed:
- Apr 21, 2016
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.1
unknown
The iThemes Security plugin for WordPress is vulnerable to insecure backup and logfile generation in versions up to, and including, 5.3.0. This is due to backup and logfiles being created in a world-readable directory. This makes it possible for unauthenticated attackers to view backup and log files.
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.1
- Disclosed:
- Apr 21, 2016
iThemes Security < 5.3.5 - Authenticated Cross-Site Scripting
low
The iThemes Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in...
- CVSS:
- 3.3
- Affected:
- up to 5.3.5
- Fixed in:
- 5.3.5
- Disclosed:
- Apr 5, 2016
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.5
unknown
The iThemes Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in...
- Affected:
- up to 5.3.5
- Fixed in:
- 5.3.5
- Disclosed:
- Apr 5, 2016
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.5
unknown
This plugin is prone to potential authenticated DOM cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 5.3.5
- Fixed in:
- 5.3.5
- Disclosed:
- Apr 5, 2016
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.6.13
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 4.6.13
- Fixed in:
- 4.6.13
- Disclosed:
- Oct 18, 2015
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.4.4
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 3.4.4
- Fixed in:
- 3.4.4
- Disclosed:
- May 15, 2015
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4
unknown
This plugin is prone to /wp-admin/admin-ajax.php license parameter stored XSS weakness.
Upgrade the plugin.
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.4
- Disclosed:
- May 15, 2015
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.6
unknown
This plugin is prone to inc/admin/content.php id_specialfile parameter stored cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 3.5.6
- Fixed in:
- 3.5.6
- Disclosed:
- May 15, 2015
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.0.0
unknown
This plugin is prone to online backup storage current_time function brute force disclosure vulnerability.
Upgrade the plugin.
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0
- Disclosed:
- May 15, 2015
iThemes Security <= 4.6.12 - Stored Cross-Site Scripting
medium
The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.6.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a us...
- CVSS:
- 6.5
- Affected:
- up to 4.6.13
- Fixed in:
- 4.6.13
- Disclosed:
- Apr 14, 2015
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.6.13
unknown
The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.6.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a us...
- Affected:
- up to 4.6.13
- Fixed in:
- 4.6.13
- Disclosed:
- Apr 14, 2015
iThemes Security < 3.6.4 - Stored Cross-Site Scripting
high
The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter in versions before 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...
- CVSS:
- 8.3
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.4
- Disclosed:
- Aug 1, 2014
Better WP Security <= 3.5.3 - Stored Cross-Site Scripting
high
The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inc/secure.php' file in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping on logged data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...
- CVSS:
- 7.2
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.4
- Disclosed:
- Aug 1, 2014
Better WP Security <= 3.6.3 - Stored Cross-Site Scripting
medium
The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will e...
- CVSS:
- 6.4
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.4
- Disclosed:
- Aug 1, 2014
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4
unknown
The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will e...
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.4
- Disclosed:
- Aug 1, 2014
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4
unknown
The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter in versions before 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.4
- Disclosed:
- Aug 1, 2014
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.4
unknown
The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inc/secure.php' file in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping on logged data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.4
- Disclosed:
- Aug 1, 2014
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.4
unknown
Better WP Security plugins is prone to a stored XSS vulnerability that allow to steal cookies or gain privileged access to the affected site.
Update the plugin to 3.5.4 version.
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.4
- Disclosed:
- Aug 2, 2013
iThemes Security < 3.4.4 - Cross-Site Scripting
medium
The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execut...
- CVSS:
- 6.5
- Affected:
- up to 3.4.4
- Fixed in:
- 3.4.4
- Disclosed:
- Aug 20, 2012
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.4.4
unknown
The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execut...
- Affected:
- up to 3.4.4
- Fixed in:
- 3.4.4
- Disclosed:
- Aug 20, 2012
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.2.5
unknown
[en] Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Aug 13, 2012
CVE-2012-4263 on NVD →
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.2.5
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263.
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Aug 13, 2012
CVE-2012-4264 on NVD →
iThemes Security < 3.2.5 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (iThemes) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.
- CVSS:
- 7.2
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- May 11, 2012
CVE-2012-4263 on NVD →
Better WP Security <= 3.2.4 - Multiple Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263.
- CVSS:
- 6.1
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.5
- Disclosed:
- May 11, 2012
CVE-2012-4264 on NVD →
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.6
unknown
- Affected:
- up to 3.5.6
- Fixed in:
- 3.5.6
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.6.13
unknown
The iThemes Security (formerly Better WP Security) WordPress plugin was affected by security vulnerability.
- Affected:
- up to 4.6.13
- Fixed in:
- 4.6.13
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.0.1
unknown
The plugin is vulnerable to protection mechanism bypass due to disclosing the login path when comments are enabled and registration is required. This makes it possible for unauthenticated attackers to discover the login page path and bypass the intended functionality of the security mechanism.
- Affected:
- up to 9.0.1
- Fixed in:
- 9.0.1
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.4
unknown
The iThemes Security (formerly Better WP Security) WordPress plugin was affected by an inc/secure.php logevent Function URL H&ling Stored XSS security vulnerability.
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.4
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.4.4
unknown
- Affected:
- up to 3.4.4
- Fixed in:
- 3.4.4
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4
unknown
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.4
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.5
unknown
The iThemes Security (formerly Better WP Security) WordPress plugin was affected by a Potential Authenticated DOM Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 5.3.5
- Fixed in:
- 5.3.5
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.9.1
unknown
Both the iThemes Security free and pro versions were affected.
- Patched in Version (iThemes Security): 7.9.1
- Patched in Version (iThemes Security Pro): 6.8.4
The bug allowed attackers to bypass the "Hide Backend" feature, that, when enabled, hides the WordPress wp-login.php and wp-admin pages.
Th...
- Affected:
- up to 7.9.1
- Fixed in:
- 7.9.1
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2
unknown
The 404 detection module needs to be enabled.
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.2
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.6
unknown
The iThemes Security (formerly Better WP Security) WordPress plugin was affected by a Lack of Capability Check security vulnerability.
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.1
unknown
The iThemes Security (formerly Better WP Security) WordPress plugin was affected by an Insecure Backup/Logfile Generation security vulnerability.
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.1
Solid Security – Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.0.0
unknown
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0