iThemes Security (formerly Better WP Security): Plugin Details
iThemes Security (formerly Better WP Security): Security Information
| Insecure versions: |
Up To 9.3.1 |
| Known since: |
2024-07-03 02:00:13 |
|
| Insecure versions: |
Up To 9.0.0 |
| Known since: |
2024-01-02 02:00:13 |
|
| Insecure versions: |
Up To 7.9.0 |
| Known since: |
2021-04-22 09:00:29 |
| Description: |
Versions of iThemes Security Free before 7.9.1 and Pro before 6.8.4 have a low severity vulnerability that allows an attacker to bypass the Hide Backend feature of the plugin, giving a false sense of security. |
|
| Insecure versions: |
Up To 7.0.2 |
| Known since: |
2018-06-27 16:19:54 |
|
| Insecure versions: |
Up To 6.9.0 |
| Known since: |
2018-03-06 02:26:33 |
|
| Insecure versions: |
Up To 5.6.1 |
| Known since: |
2016-10-10 15:00:34 |
|
| Insecure versions: |
Up To 5.3.5 |
| Known since: |
2016-04-26 23:17:38 |
|
| Insecure versions: |
Up To 5.3.4 |
| Known since: |
2016-04-06 19:13:44 |
|
| Insecure versions: |
Up To 3.2.4 |
| Known since: |
2015-11-25 04:38:27 |
|
| Insecure versions: |
Up To 4.6.12 |
| Known since: |
2015-09-13 21:01:31 |
|
| Insecure versions: |
Up To 3.2.4 |
| Known since: |
2014-03-18 20:05:53 |
| Description: |
Better WP Security <= 3.2.4 - Cross Site Scripting |
| More Information: |
|
|
| Insecure versions: |
Up To 3.4.3 |
| Known since: |
2014-03-18 20:05:53 |
| Description: |
Better WP Security 3.4.3 - Multiple XSS |
| More Information: |
|
|
| Insecure versions: |
Up To 3.5.3 |
| Known since: |
2014-03-18 20:05:53 |
| Description: |
Better WP Security <= 3.5.3 - inc/secure.php logevent Function URL Handling Stored XSS |
|
| Insecure versions: |
Up To 3.5.5 |
| Known since: |
2014-03-18 20:05:53 |
| Description: |
Better WP Security 3.5.5 - inc/admin/content.php id_specialfile Parameter Stored XSS |
|
| Insecure versions: |
Up To 3.6.3 |
| Known since: |
2014-03-18 20:05:53 |
| Description: |
Better WP Security 3.6.3 - /wp-admin/admin-ajax.php license Parameter Stored XSS Weakness |
| More Information: |
|
|
| Insecure versions: |
Up To 3.6.3 |
| Known since: |
2014-03-18 20:05:53 |
| Description: |
Better WP Security 3.6.3 - /wp-admin/admin-ajax.php license Parameter Stored XSS Weakness |
| More Information: |
|
|
iThemes Security (formerly Better WP Security): Safety Recommendations
We have rated iThemes Security (formerly Better WP Security) as
Good (current version safe) which means
that we have found vulnerabilities in older versions.
We recommend that
you only use the latest version of iThemes Security (formerly Better WP Security).