Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] <= 3.2.8 (unfixed)
unknown
[en] Missing Authorization vulnerability in StellarWP iThemes Sync ithemes-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through <= 3.2.8.
- Affected:
- up to 3.2.8
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-27056 on NVD →
Solid Central – Site Management, Backups, Security, and Reporting <= 3.2.8 - Missing Authorization
medium
The Solid Central – Site Management, Backups, Security, and Reporting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to per...
- CVSS:
- 4.3
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.9
- Disclosed:
- Jan 11, 2026
CVE-2026-27056 on NVD →
Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 2.1.14 (closed)
unknown
[en] Missing Authorization vulnerability in SolidWP iThemes Sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through 2.1.13.
- Affected:
- up to 2.1.14
- Fixed in:
- 2.1.14
- Disclosed:
- Dec 13, 2024
CVE-2023-40001 on NVD →
Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 3.0.1 (closed)
unknown
Update the WordPress Solid Central plugin to the latest available version (at least 3.0.1).
Robin Wood discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress iThemes Sync Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML...
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Nov 9, 2023
Solid Central <= 3.0.0 - Stored Cross-Site Scripting via packages
medium
The Solid Central – Site Management, Backups, Security, and Reporting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via malicious package names in all versions up to and including 3.0.0 due to insufficient output escaping. This makes it possible for attackers able to compromise the packages retr...
- CVSS:
- 5.4
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Nov 7, 2023
Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 3.0.1 (closed)
unknown
The Solid Central – Site Management, Backups, Security, and Reporting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via malicious package names in all versions up to and including 3.0.0 due to insufficient output escaping. This makes it possible for attackers able to compromise the packages retr...
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Nov 7, 2023
iThemes Sync <= 2.1.13 - Cross-Site Request Forgery and Missing Authorization via 'hide_authenticate_notice'
medium
The iThemes Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.13. This is due to missing or incorrect nonce validation on the hide_authenticate_notice function. This makes it possible for unauthenticated attackers to hide admin notices via a forged request grant...
- CVSS:
- 4.3
- Affected:
- up to 2.1.14
- Fixed in:
- 2.1.14
- Disclosed:
- Aug 25, 2023
CVE-2023-40001 on NVD →
Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 2.1.14 (closed)
unknown
The iThemes Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.13. This is due to missing or incorrect nonce validation on the hide_authenticate_notice function. This makes it possible for unauthenticated attackers to hide admin notices via a forged request grant...
- Affected:
- up to 2.1.14
- Fixed in:
- 2.1.14
- Disclosed:
- Aug 25, 2023
Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 2.0.18 (closed)
unknown
Insufficient Secure Key Validation vulnerability found in WordPress iThemes Sync plugin (versions <= 2.0.17).
- Affected:
- up to 2.0.18
- Fixed in:
- 2.0.18
- Disclosed:
- Oct 10, 2019
iThemes Sync <= 2.0.17 - Authentication Bypass
critical
The iThemes Sync plugin for WordPress is vulnerable to authentication bypass due to a missing validation on the secure key in versions up to, and including, 2.0.17. This makes it possible for unauthenticated attackers to add their own secure key leading to a complete compromise of the affected website.
- CVSS:
- 9.8
- Affected:
- up to 2.0.18
- Fixed in:
- 2.0.18
- Disclosed:
- Oct 9, 2019
Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 2.0.18 (closed)
unknown
The iThemes Sync plugin for WordPress is vulnerable to authentication bypass due to a missing validation on the secure key in versions up to, and including, 2.0.17. This makes it possible for unauthenticated attackers to add their own secure key leading to a complete compromise of the affected website.
- Affected:
- up to 2.0.18
- Fixed in:
- 2.0.18
- Disclosed:
- Oct 9, 2019
Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 2.0.18 (closed)
unknown
iThemes Sync allows users to manage multiple websites from a single dashboard. This vulnerability, affecting secret key validation, could lead to full compromise of a WordPress site.
- Affected:
- up to 2.0.18
- Fixed in:
- 2.0.18
Solid Central – Site Management, Backups, Security, and Reporting [ithemes-sync] < 3.0.1 (closed)
unknown
The plugin is vulnerable to Stored Cross-Site Scripting via via malicious package names in all versions up to and including 3.0.0 due to insufficient output escaping. This makes it possible for attackers able to compromise the packages retrieved from the iThemes API to inject arbitrary web scripts in pages that will ex...
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database