CVE-2022-44593
Solid Security – Password, Two Factor Authentication, and Brute Force Protection
Minimum safe version
9.3.2
Update to 9.3.2 or later to address 43 fixable vulnerabilities
Solid Security Basic < 9.0.1 - Unauthenticated Login Page Disclosure
WordPress Solid Security Plugin <= 9.0.0 is vulnerable to Sensitive Data Exposure
Solid Security Basic <= 9.0.0 - Unauthenticated Login Page Disclosure
CVE-2023-28786
iThemes Security < 3.4.4 - Cross-Site Scripting
Better WP Security <= 3.6.3 - Stored Cross-Site Scripting
iThemes Security < 3.6.4 - Stored Cross-Site Scripting
Better WP Security <= 3.5.3 - Stored Cross-Site Scripting
iThemes Security <= 4.6.12 - Stored Cross-Site Scripting
iThemes Security < 5.3.5 - Authenticated Cross-Site Scripting
iThemes Security < 5.3.1 - Insecure Backup/Logfile Generation
iThemes Security <= 5.3.5 - Missing Capabilities Check
iThemes Security <= 5.6.1 - Sensitive Information Exposure via Diff Response
iThemes Security <= 5.6.1 - Stored Cross-Site Scripting
iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass
wpscan.com
wpscan.com
wpscan.com
wpscan.com
Better WP Security <= 3.5.3 - inc/secure.php logevent Function URL H&ling Stored XSS
iThemes Security 3.0-4.6.12 – Stored Cross-Site Scripting (XSS)
iThemes Security <= 5.3.4 - Potential Authenticated DOM Cross-Site Scripting (XSS)
iThemes Security <= 5.3.0 - Insecure Backup/Logfile Generation
iThemes Security <= 5.3.5 - Lack of Capability Check
iThemes Security <= 5.6.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
iThemes Security Free (< 7.9.1) & Pro (< 6.8.4) - Hide Backend Bypass
WordPress Better WP Security Plugin <= 3.6.3 - XSS
WordPress Better WP Security Plugin <= 3.5.5 - Stored XSS
WordPress Better WP Security Plugin <= 3.6.3 - Stored XSS
WordPress Better WP Security Plugin <= 3.4.3 - Multiple XSS
WordPress Better WP Security Plugin - Stored XSS
WordPress iThemes Security Plugin <= 4.6.12 - Stored XSS
WordPress iThemes Security Plugin <= 5.3.4 - DOM XSS
WordPress iThemes Security Plugin <= 5.3.0 - Bypass
WordPress iThemes Security Plugin <= 5.3.5 - Bypass
WordPress iThemes Security Plugin <= 5.6.1 - Stored XSS
WordPress iThemes Security plugin <= 7.9.0 - Hide Backend Bypass vulnerability
CVE-2012-4264
CVE-2012-4263
WordPress iThemes Security <=6.9.0 - Cross-Site Scripting (XSS) vulnerability
WordPress iThemes Security plugin <= 7.0.2 - Authenticated SQL Injection (SQLi) vulnerability
CVE-2020-36176