iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass
medium
It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4
- CVSS:
- 5.3
- Affected:
- up to 6.8.4
- Fixed in:
- 6.8.4
- Disclosed:
- Apr 22, 2021
iThemes Security Pro [ithemes-security-pro] < 6.8.4
unknown
It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4
- Affected:
- up to 6.8.4
- Fixed in:
- 6.8.4
- Disclosed:
- Apr 22, 2021
iThemes Security Pro [ithemes-security-pro] < 6.8.4
unknown
Hide Backend Bypass vulnerability discovered by Julio Potier (SecuPress) in WordPress iThemes Security Pro premium plugin (versions <= 6.8.3).
- Affected:
- up to 6.8.4
- Fixed in:
- 6.8.4
- Disclosed:
- Apr 21, 2021
iThemes Security Pro [ithemes-security-pro] < 6.8.4
unknown
Both the iThemes Security free and pro versions were affected.
- Patched in Version (iThemes Security): 7.9.1
- Patched in Version (iThemes Security Pro): 6.8.4
The bug allowed attackers to bypass the "Hide Backend" feature, that, when enabled, hides the WordPress wp-login.php and wp-admin pages.
Th...
- Affected:
- up to 6.8.4
- Fixed in:
- 6.8.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database