Medium 4.3
2026-02-19< 3.2.9
CVE-2026-27056
Minimum safe version
3.2.9
Update to 3.2.9 or later to address 9 fixable vulnerabilities
CVE-2026-27056
Solid Central < 3.0.1 - Stored Cross-Site Scripting via packages
WordPress iThemes Sync Plugin < 3.0.1 is vulnerable to Cross Site Scripting (XSS)
Solid Central <= 3.0.0 - Stored Cross-Site Scripting via packages
CVE-2023-40001
iThemes Sync <= 2.1.13 - Cross-Site Request Forgery and Missing Authorization via 'hide_authenticate_notice'
iThemes Sync <= 2.0.17 - Insufficient Secure Key Validation
iThemes Sync <= 2.0.17 - Authentication Bypass
WordPress iThemes Sync plugin <= 2.0.17 - Insufficient Secure Key Validation vulnerability