plugin

Ithemes Sync Vulnerabilities

13 known security issues reported for the Ithemes Sync WordPress plugin. Most recent disclosed Feb 19, 2026.

1 critical 3 medium

Running Ithemes Sync on your site? Check whether your installed version is affected.

Scan your site free

Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] <= 3.2.8 (unfixed)

unknown

[en] Missing Authorization vulnerability in StellarWP iThemes Sync ithemes-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through <= 3.2.8.

Affected:
up to 3.2.8
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-27056 on NVD →

Solid Central – Site Management, Backups, Security, and Reporting <= 3.2.8 - Missing Authorization

medium

The Solid Central – Site Management, Backups, Security, and Reporting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to per...

CVSS:
4.3
Affected:
up to 3.2.8
Fixed in:
3.2.9
Disclosed:
Jan 11, 2026

CVE-2026-27056 on NVD →

Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 2.1.14 (closed)

unknown

[en] Missing Authorization vulnerability in SolidWP iThemes Sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through 2.1.13.

Affected:
up to 2.1.14
Fixed in:
2.1.14
Disclosed:
Dec 13, 2024

CVE-2023-40001 on NVD →

Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 3.0.1 (closed)

unknown

Update the WordPress Solid Central plugin to the latest available version (at least 3.0.1). Robin Wood discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress iThemes Sync Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML...

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Nov 9, 2023

Solid Central <= 3.0.0 - Stored Cross-Site Scripting via packages

medium

The Solid Central – Site Management, Backups, Security, and Reporting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via malicious package names in all versions up to and including 3.0.0 due to insufficient output escaping. This makes it possible for attackers able to compromise the packages retr...

CVSS:
5.4
Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Nov 7, 2023

Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 3.0.1 (closed)

unknown

The Solid Central – Site Management, Backups, Security, and Reporting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via malicious package names in all versions up to and including 3.0.0 due to insufficient output escaping. This makes it possible for attackers able to compromise the packages retr...

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Nov 7, 2023

iThemes Sync <= 2.1.13 - Cross-Site Request Forgery and Missing Authorization via 'hide_authenticate_notice'

medium

The iThemes Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.13. This is due to missing or incorrect nonce validation on the hide_authenticate_notice function. This makes it possible for unauthenticated attackers to hide admin notices via a forged request grant...

CVSS:
4.3
Affected:
up to 2.1.14
Fixed in:
2.1.14
Disclosed:
Aug 25, 2023

CVE-2023-40001 on NVD →

Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 2.1.14 (closed)

unknown

The iThemes Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.13. This is due to missing or incorrect nonce validation on the hide_authenticate_notice function. This makes it possible for unauthenticated attackers to hide admin notices via a forged request grant...

Affected:
up to 2.1.14
Fixed in:
2.1.14
Disclosed:
Aug 25, 2023

Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 2.0.18 (closed)

unknown

Insufficient Secure Key Validation vulnerability found in WordPress iThemes Sync plugin (versions <= 2.0.17).

Affected:
up to 2.0.18
Fixed in:
2.0.18
Disclosed:
Oct 10, 2019

iThemes Sync <= 2.0.17 - Authentication Bypass

critical

The iThemes Sync plugin for WordPress is vulnerable to authentication bypass due to a missing validation on the secure key in versions up to, and including, 2.0.17. This makes it possible for unauthenticated attackers to add their own secure key leading to a complete compromise of the affected website.

CVSS:
9.8
Affected:
up to 2.0.18
Fixed in:
2.0.18
Disclosed:
Oct 9, 2019

Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 2.0.18 (closed)

unknown

The iThemes Sync plugin for WordPress is vulnerable to authentication bypass due to a missing validation on the secure key in versions up to, and including, 2.0.17. This makes it possible for unauthenticated attackers to add their own secure key leading to a complete compromise of the affected website.

Affected:
up to 2.0.18
Fixed in:
2.0.18
Disclosed:
Oct 9, 2019

Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 2.0.18 (closed)

unknown

iThemes Sync allows users to manage multiple websites from a single dashboard. This vulnerability, affecting secret key validation, could lead to full compromise of a WordPress site.

Affected:
up to 2.0.18
Fixed in:
2.0.18

Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 3.0.1 (closed)

unknown

The plugin is vulnerable to Stored Cross-Site Scripting via via malicious package names in all versions up to and including 3.0.0 due to insufficient output escaping. This makes it possible for attackers able to compromise the packages retrieved from the iThemes API to inject arbitrary web scripts in pages that will ex...

Affected:
up to 3.0.1
Fixed in:
3.0.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database