{"error":0,"message":null,"data":{"name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection","plugin":"better-wp-security","link":"https:\/\/wordpress.org\/plugins\/better-wp-security\/","latest":"1789581300","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"221e54e97f5f4372c91b55aa0c1472d3a15b4c60a91b78051ddd616f7bd14e4d","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-36176","name":"CVE-2020-36176","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36176","description":"[en] The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.","date":"2021-01-06"},{"id":"8c7396cba9088f7ae5e0a53a3beed75b6fc142d1","name":"iThemes Security <= 7.6.1 - Broken Password Mechanism","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-761-broken-password-mechanism","description":"The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.","date":"2021-01-06"},{"id":"7f45c02a-9b41-483e-80f3-fb51b1519487","name":"iThemes Security &lt; 7.7.0 - New-Password Requirements Not Enforced Until second Login","link":"https:\/\/wpscan.com\/vulnerability\/7f45c02a-9b41-483e-80f3-fb51b1519487","description":"The plugin did not enforce new-password requirements for existing accounts until the second login occurred, which could leave an account configured with a potentially weak password until the user changes it","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}]}},{"uuid":"a81ba094550b9a36da189393f57062c155ce5d934ac9a53bdc5d267e3f9f8d75","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-12636","name":"CVE-2018-12636","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-12636","description":"[en] The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.","date":"2018-06-22"},{"id":"c5c2dd650ece68d0edda8b5c772ea89a9e7bc28d","name":"WordPress iThemes Security plugin <= 7.0.2 - Authenticated SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-ithemes-security-plugin-7-0-2-authenticated-sql-injection-sqli-vulnerability","description":"Authenticated SQL Injection (SQLi) vulnerability found by \u00c7lirim Emini in WordPress iThemes Security plugin (versions <= 7.0.2).","date":"2018-06-25"},{"id":"1092cabd-41c8-43ae-a08e-538c5bb575b9","name":"iThemes Security &lt;= 7.0.2 - Authenticated SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/1092cabd-41c8-43ae-a08e-538c5bb575b9","description":"The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.\r\n\r\nVulnerability description:\r\n\r\niThemes Security appears to be vulnerable to time-based SQL-Injection.\r\n\r\nParameter orderby is vulnerable because backend variable $sort_by_column\r\nis not escaped.\r\n\r\nPrivileges required: Admin user.\r\n\r\nTechnical details:\r\n\r\nFile: better-wp-security\/core\/admin-pages\/logs-list-table.php\r\nLine 271: if ( isset( $_GET[&#039;\u200b orderby\u200b &#039;], $_GET[&#039;order&#039;] ) ) {\r\nLine 272: $\u200b sort_by_column\u200b = $_GET[&#039;\u200b orderby\u200b &#039;];\r\n\r\nFile: better-wp-security\/core\/lib\/log-util.php\r\nLine 168: $query .= &#039; ORDER BY &#039; . implode( &#039;, &#039;, $\u200b sort_by_column\u200b ));","date":null},{"id":"6d0bb8c158fe7193eebb8bafb3127a31d04bd15d","name":"iThemes Security <= 7.0.2 - Authenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-702-authenticated-sql-injection","description":"The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.","date":"2018-06-25"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"a89f8eaf6e53c0b0fe68fd43aa1f79841fb97dd9ccc3e4b2ebd2bc2e33ad44b2","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 6.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-7433","name":"CVE-2018-7433","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-7433","description":"[en] The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.","date":"2018-03-02"},{"id":"c6292201a1785a79d4ceb7342f32601a55cd0cb0","name":"WordPress iThemes Security <=6.9.0 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-ithemes-security-6-9-0-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability found by Pawe\u0142 Kury\u0142owicz in WordPress iThemes Security (versions <=6.9.0).","date":"2018-03-05"},{"id":"61f82c56-7f01-4724-8001-6004f1dac7cb","name":"iThemes Security &lt;= 6.9.0 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/61f82c56-7f01-4724-8001-6004f1dac7cb","description":"The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.","date":null},{"id":"667207dacc750957eec5732ed2b6c4e9252e4574","name":"iThemes Security <= 6.9.0 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-690-cross-site-scripting","description":"The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.","date":"2018-03-05"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-532","name":"Insertion of Sensitive Information into Log File","description":"The product writes sensitive information to a log file."}]}},{"uuid":"621cd440f33ec66efc80adc8340753c469d8d34f605be89ca87294d841b94d40","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2012-4263","name":"CVE-2012-4263","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2012-4263","description":"[en] Cross-site scripting (XSS) vulnerability in inc\/admin\/content.php in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.","date":"2012-08-13"},{"id":"ad98e3b74376662981d4742c645618bda63af2c7","name":"WordPress Better WP Security Plugin <= 3.2.4 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-better-wp-security-plugin-3-2-4-xss","description":"Because of this vulnerability in inc\/admin\/content.php, the attackers can inject arbitrary web script or HTML via the HTTP_USER_AGENT header.\nUpdate the plugin.","date":"2012-08-13"},{"id":"d390c4734553543778f255bcd4c7fc2cb8cdc0d9","name":"iThemes Security < 3.2.5 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-325-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in inc\/admin\/content.php in the Better WP Security (iThemes) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.","date":"2012-05-11"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"27cb49829ecea4d06011df8db8031dd062c2f1de18970e1ed0eb2027620a48d7","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2012-4264","name":"CVE-2012-4264","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2012-4264","description":"[en] Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to \"server variables,\" a different vulnerability than CVE-2012-4263.","date":"2012-08-13"},{"id":"6568b0d4585cc09f067d9d330970794f07743351","name":"WordPress Better WP Security Plugin <= 3.2.4 - Multiple XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-better-wp-security-plugin-3-2-4-multiple-xss","description":"Because of this vulnerabilities, the  attackers can inject arbitrary web script or HTML via unspecified vectors related to \"server variables\".\nUpdate the plugin.","date":"2012-08-13"},{"id":"bc1e3530-e131-44ec-a261-1e2776d57917","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/bc1e3530-e131-44ec-a261-1e2776d57917","description":null,"date":null},{"id":"880fd31904c57387d788c93f0a4955f48b466cfc","name":"Better WP Security <= 3.2.4 - Multiple Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/better-wp-security-324-multiple-cross-site-scripting","description":"Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to \"server variables,\" a different vulnerability than CVE-2012-4263.","date":"2012-05-11"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f4be131f9f336236e9d910ba846931d9bb8bc7ab4332295d79325e641f189796","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6912bc9c8575d8f0f4c7d41ca8c085751d5b703b","name":"WordPress iThemes Security plugin <= 7.9.0 - Hide Backend Bypass vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-ithemes-security-plugin-7-9-0-hide-backend-bypass-vulnerability","description":"Hide Backend Bypass vulnerability discovered by Julio Potier (SecuPress) in WordPress iThemes Security plugin (versions <= 7.9.0).","date":"2021-04-21"}],"impact":[]},{"uuid":"7ee37bec50693ced52c5500b30cb2bf493a392170ec6c6a0137840752f3328fd","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fe0d8d89afc6b4fb2cf1cfc23bcb53cd852e8e29","name":"WordPress iThemes Security Plugin <= 5.6.1 - Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-ithemes-security-plugin-5-6-1-stored-xss","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2016-10-06"}],"impact":[]},{"uuid":"edd7e2db312107fa740406e2ffc3d6eeeaffe57c4e62e909a249a46a8638f195","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8a40e42f5133edf9e9ecaab9dd44f5ef21ec4af8","name":"WordPress iThemes Security Plugin <= 5.3.5 - Bypass","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-ithemes-security-plugin-5-3-5-bypass","description":"This plugin is prone to lack of capability check vulnerability. It allows anyone \u201cfake click\u201d on this button, hiding the changes to the administrator.\nUpdate the plugin.","date":"2016-04-25"}],"impact":[]},{"uuid":"46356f0a613f614c2d6e14e43848bc7938d676d2898d6a265a21eed6978e660a","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"543cfd53aafbf580a08f01a9a3e1b540bf468cfd","name":"WordPress iThemes Security Plugin <= 5.3.0 - Bypass","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-ithemes-security-plugin-5-3-0-bypass","description":"This plugin is prone to insecure backup and logfile generation vulnerability.\nUpdate the plugin.","date":"2016-04-22"}],"impact":[]},{"uuid":"56a86fbeee87b0d5c56b583ac78f186d3e1b1df7618bc9a90182b6ed031ba33b","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"afc2b84371636110d5d0c55d0ddc1ff0f40ba585","name":"WordPress iThemes Security Plugin <= 5.3.4 - DOM XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-ithemes-security-plugin-5-3-4-dom-xss","description":"This plugin is prone to potential authenticated DOM cross site scripting vulnerability.\nUpdate the plugin.","date":"2016-04-05"}],"impact":[]},{"uuid":"a7d97a12353ceb0174865f3ff6f4f3323fd0c4fce4c788bea86eda3bcb5f4b31","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.6.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ae0e40ba1d6d102429e879fe3061c51d06391356","name":"WordPress iThemes Security Plugin <= 4.6.12 - Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-ithemes-security-plugin-4-6-12-stored-xss","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-10-18"}],"impact":[]},{"uuid":"c78bb5610439206e51f733325a28281481b869c8f7b46a44d5e3205330663215","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"33940f1012fa1bf55d2b1c456d711f0bd80d4383","name":"WordPress Better WP Security Plugin - Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-better-wp-security-plugin-stored-xss","description":"Better WP Security plugins is prone to a stored XSS vulnerability that allow to  steal cookies or gain privileged access to the affected site.\nUpdate the plugin to 3.5.4 version.","date":"2013-08-02"}],"impact":[]},{"uuid":"588e497ede85278874ef935b2cd4183f437d1a42a115e5ab113912c46e175896","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1c7e52909769ef9360123c410f8346105889d13a","name":"WordPress Better WP Security Plugin <= 3.4.3 - Multiple XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-better-wp-security-plugin-3-4-3-multiple-xss","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"6e14a1f922d022e283c60a9624a9de76542d3067e0f458990dddce624d603044","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4b5f8c2cfae2c6bce6f48b9e25ef461b66430307","name":"WordPress Better WP Security Plugin <= 3.6.3 - Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-better-wp-security-plugin-3-6-3-stored-xss","description":"This plugin is prone to \/wp-admin\/admin-ajax.php license parameter stored XSS weakness.\nUpgrade the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"a868964df1478a5c79d0aa82e4cd60d26fe4f35b2b0c5cdc430fa2a6ea6d4324","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4a6112e7251ad56045e97df2deef9605c7cf135b","name":"WordPress Better WP Security Plugin <= 3.5.5 - Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-better-wp-security-plugin-3-5-5-stored-xss","description":"This plugin is prone to inc\/admin\/content.php id_specialfile parameter stored cross site scripting vulnerability.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"174792ae302a597a42e391ee6c6120a8dd20bc6676f8c2a2f19511cd17cffe4e","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"52d6cd29ec3b567ca89fea4101575aede0c05297","name":"WordPress Better WP Security Plugin <= 3.6.3 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-better-wp-security-plugin-3-6-3-xss","description":"This plugin is prone to online backup storage current_time function brute force disclosure vulnerability.\nUpgrade the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"e0676df0a2c0671e36df73f39027c8dc443b4fc6eefa08d84c48d761e9cb8076","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"42fdb534-3aef-4ed7-94a8-4cfe8ff977e1","name":"iThemes Security Free (&lt; 7.9.1) &amp; Pro (&lt; 6.8.4) - Hide Backend Bypass","link":"https:\/\/wpscan.com\/vulnerability\/42fdb534-3aef-4ed7-94a8-4cfe8ff977e1","description":"Both the iThemes Security free and pro versions were affected.\r\n\r\n- Patched in Version (iThemes Security): 7.9.1\r\n- Patched in Version (iThemes Security Pro): 6.8.4\r\n\r\nThe bug allowed attackers to bypass the &quot;Hide Backend&quot; feature, that, when enabled, hides the WordPress wp-login.php and wp-admin pages.\r\n\r\nThis could allow attackers to conduct brute force or other attacks against the &quot;hidden&quot; pages, giving a false sense of security.\r\n\r\nThis vulnerability was discovered and responsibly disclosed by Julio Potier of SecuPress.\r\n\r\nUpdate to version 7.9.1 of iThemes Security and 6.8.4 of iThemes Security Pro to receive the Hide Backed bypass workaround patch.","date":null}],"impact":[]},{"uuid":"5d32c1b0b612959e5d58059def6693652b43093f4a1d7a5949ebdd3f984b9f5c","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b01671ba-c974-4fff-a684-dbd8cc265996","name":"iThemes Security &lt;= 5.6.1 - Unauthenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/b01671ba-c974-4fff-a684-dbd8cc265996","description":"The 404 detection module needs to be enabled.","date":null}],"impact":[]},{"uuid":"30744c9ff5aca81696b3956fb003fe871fe7f89e6e245b32a97cdba2db791fb3","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c951364e-e6a4-40fa-9001-741a386c9825","name":"iThemes Security &lt;= 5.3.5 - Lack of Capability Check","link":"https:\/\/wpscan.com\/vulnerability\/c951364e-e6a4-40fa-9001-741a386c9825","description":"The iThemes Security (formerly Better WP Security) WordPress plugin was affected by a Lack of Capability Check security vulnerability.","date":null}],"impact":[]},{"uuid":"6918d9ed05836924be9ac897cf417986265af5112ff1eb57ac9557c73973de5d","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"99784e81-8085-4da4-a1a4-bd64d9437c55","name":"iThemes Security &lt;= 5.3.0 - Insecure Backup\/Logfile Generation","link":"https:\/\/wpscan.com\/vulnerability\/99784e81-8085-4da4-a1a4-bd64d9437c55","description":"The iThemes Security (formerly Better WP Security) WordPress plugin was affected by an Insecure Backup\/Logfile Generation security vulnerability.","date":null}],"impact":[]},{"uuid":"d4ecd814b2654066e0962105dca54186d7ef6a693f6590e13f781ed1e5d4cb38","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"55fe42ef-eba4-4992-bbc0-ebbe5abf63a1","name":"iThemes Security &lt;= 5.3.4 - Potential Authenticated DOM Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/55fe42ef-eba4-4992-bbc0-ebbe5abf63a1","description":"The iThemes Security (formerly Better WP Security) WordPress plugin was affected by a Potential Authenticated DOM Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"45fe267451a595d7b433ea312e9ba7410863e2c001e1b22c49866a9f6907e814","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.6.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"63f35fe6-b779-4c9e-b260-f6fb9cd0e231","name":"iThemes Security 3.0-4.6.12 &ndash; Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/63f35fe6-b779-4c9e-b260-f6fb9cd0e231","description":"The iThemes Security (formerly Better WP Security) WordPress plugin was affected by   security vulnerability.","date":null}],"impact":[]},{"uuid":"7e6d07368bbfe60bb8d3cbdd218b924afb30df76b6115e8dd226ee4042316cf1","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"aca181eb-a018-4010-90fe-1746c7a1e976","name":"Better WP Security &lt;= 3.5.3 - inc\/secure.php logevent Function URL H&amp;ling Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/aca181eb-a018-4010-90fe-1746c7a1e976","description":"The iThemes Security (formerly Better WP Security) WordPress plugin was affected by an inc\/secure.php logevent Function URL H&amp;ling Stored XSS security vulnerability.","date":null}],"impact":[]},{"uuid":"89e7a1d78bc310674c323eb85021b69f9a174c22475d6a200c31e9c124211863","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7227dcca-19c4-4125-af3f-04e6ccafdce2","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/7227dcca-19c4-4125-af3f-04e6ccafdce2","description":null,"date":null}],"impact":[]},{"uuid":"ee875f22c487ede726d12595860d84e50254e69a2062c52013b33018a98d13d6","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"84e3b0f1-534b-4504-b66a-d46211f66d11","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/84e3b0f1-534b-4504-b66a-d46211f66d11","description":null,"date":null}],"impact":[]},{"uuid":"7a83365fe0a6bca9be756318e333437d920c06bf67c575f06725546b44aaca46","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ba1836f2-4abe-400b-9290-8bdab0a7d105","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/ba1836f2-4abe-400b-9290-8bdab0a7d105","description":null,"date":null}],"impact":[]},{"uuid":"3ea016682ef5b42beb5776d29f4ca504b41cae00f4bc57526515ffb5fb772c91","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a9098f41-65e3-4435-8d62-478c17c1963b","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/a9098f41-65e3-4435-8d62-478c17c1963b","description":null,"date":null}],"impact":[]},{"uuid":"5d2c22d584ecea696e3935d7d700c0ad8c572ce7ee0c33bbb39005d2872babd3","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 7.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"635a923295fe04f78b5819b6f3bc0ed9a6f088a3","name":"iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/ithemes-security-791-and-ithemes-security-pro-684-hidden-login-bypass","description":"It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4","date":"2021-04-22"}],"impact":[]},{"uuid":"b34d239a275eb97cc222db2137ba253a54455c972536c1b15d37452c91d21c73","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"430b0a42ed24afe8ea7e78526c5b7cde6e5a7777","name":"iThemes Security <= 5.6.1 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-561-stored-cross-site-scripting","description":"The iThemes Security for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.\r\n\r\n\"Security Fix: Updated log output to prevent specific kinds of logged requests from displaying without sanitization. Thanks to Slavco Mihajloski for contacting us about this issue.\" ~ https:\/\/wordpress.org\/plugins\/better-wp-security\/#developers","date":"2016-10-06"}],"impact":[]},{"uuid":"b377c53878b5954ec6f7dafb8fd67824ad62ef5521e04f3d8ac9650c4be3b36c","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"644b563ee3339b1ba6d9dd93f3d8da484fca06b6","name":"iThemes Security <= 5.6.1 - Sensitive Information Exposure via Diff Response","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-561-sensitive-information-exposure-via-diff-response","description":"The iThemes Security plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including 5.6.1, due to invalid username\/password combinations returning different HTTP headers on response. This makes it possible for attackers to observe differences in responses to determine valid usernames on the site (username enumeration).","date":"2016-09-27"}],"impact":[]},{"uuid":"0dcae88c3a13efcbcc1ec070d70b373cd54e0394b3cf6cb549a4e5e38fe5e20b","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"111b48ea654003c1b4d6d783b658d9ffc0529b71","name":"iThemes Security <= 5.3.5 - Missing Capabilities Check","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-535-missing-capabilities-check","description":"The iThemes Security plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_itsec_file_change_warning_ajax function in versions up to, and including, 5.3.5. This makes it possible for authenticated attackers to perform administrative actions.","date":"2016-04-25"}],"impact":[]},{"uuid":"6e5df58f7be3ba8396dea3a206d10918765b632fbc0f61c7a60a804d4d403a7b","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8b901ecc712ae441afa86c72af886c143feda3db","name":"iThemes Security < 5.3.1 - Insecure Backup\/Logfile Generation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-531-insecure-backuplogfile-generation","description":"The iThemes Security plugin for WordPress is vulnerable to insecure backup and logfile generation in versions up to, and including, 5.3.0. This is due to backup and logfiles being created in a world-readable directory. This makes it possible for unauthenticated attackers to view backup and log files.","date":"2016-04-21"}],"impact":[]},{"uuid":"88e9d42afc26f6a69a12257b6fcf965004ceda0a56f5c0e124805e22cd23ae0e","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 5.3.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1a4790954a009aa6156cc9e03018079ba0509249","name":"iThemes Security < 5.3.5 - Authenticated Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-535-authenticated-cross-site-scripting","description":"The iThemes Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2016-04-05"}],"impact":[]},{"uuid":"88cebdf2e9ff86767f9a1324ad2690e3e1b4accee8a2eac197672a6339c07d77","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 4.6.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"52502b5bf9b726dd703e6c231aaebab779e39875","name":"iThemes Security <= 4.6.12 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-4612-stored-cross-site-scripting","description":"The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.6.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2015-04-14"}],"impact":[]},{"uuid":"7460182f1c59b9a06864fccd91b7798c23eb6c00cde95364d4660a434def16ff","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"be7132443f1fa9fc293feb6ad66dc1755773f41a","name":"Better WP Security <= 3.5.3 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/better-wp-security-353-stored-cross-site-scripting","description":"The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inc\/secure.php' file in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping on logged data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2014-08-01"}],"impact":[]},{"uuid":"7b89465a13f0b405c26e6156c0dc600831b8654892d096e65f366c8579623ba7","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2309b491e80a841a137f72a54af2a5a19ac08d7a","name":"iThemes Security < 3.6.4 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-364-stored-cross-site-scripting","description":"The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018license\u2019 parameter in versions before 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2014-08-01"}],"impact":[]},{"uuid":"e203774552e008454e9df789ad3be4cffd1ce67823fa6cddd1d8349f9e046325","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2380931eb94bdb4d5653c347b8f31f5aae95046d","name":"Better WP Security <= 3.6.3 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/better-wp-security-363-stored-cross-site-scripting","description":"The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018license\u2019 parameter in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2014-08-01"}],"impact":[]},{"uuid":"b06be358fde845c101443c0482a4933e2e04e6817c53b035aaf8b01eceb10ef2","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 3.4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"07ff64442820ce1671bc5d7095e7dce704705e01","name":"iThemes Security < 3.4.4 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-344-cross-site-scripting","description":"The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2012-08-20"}],"impact":[]},{"uuid":"c3e0db30dde2a186e9164e9da1eebce9ac5fe91b24953cc75e3bf5dca5fcff3a","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 8.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-28786","name":"CVE-2023-28786","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-28786","description":"[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security \u2013 Password, Two Factor Authentication, and Brute Force Protection.This issue affects Solid Security \u2013 Password, Two Factor Authentication, and Brute Force Protection: from n\/a through 8.1.4.","date":"2023-12-29"},{"id":"d5f3d897d620f78c9fcfc1aa943fcb30a90dd996","name":"WordPress  iThemes Security Plugin  <= 8.1.4 is vulnerable to Open Redirection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-ithemes-security-plugin-8-1-4-open-redirection-via-host-header-vulnerability","description":"Update the WordPress iThemes Security plugin to the latest available version (at least 8.1.5).\nnlpro discovered and reported this Open Redirection vulnerability in WordPress iThemes Security Plugin. This could allow a malicious actor to redirect users from one site to the other due to the redirect URL not being validated. Users could be tricked to visiting a legitimate site to then be redirected to a malicious site and cause a phishing incident. This vulnerability has been fixed in version 8.1.5.","date":"2023-03-27"},{"id":"37f3e4dbabfa6f1b9ff846027d80a8c0851693c0","name":"iThemes Security <= 8.1.4 - Open Redirection via redirect_to_https","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/ithemes-security-814-open-redirection-via-redirect-to-https","description":"The iThemes Security plugin for WordPress is vulnerable to open redirection in versions up to, and including, 8.1.4. This is due to the use of wp_redirect instead of wp_safe_redirect in the redirect_to_https function. This makes it possible for unauthenticated attackers to arbitrarily redirect users via a forged request granted they can trick a the user into performing an action such as clicking on a link.","date":"2023-03-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"3.7","severity":"l","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"3.7","severity":"low","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"acb830a235b8c45f70ffafffe98bf9437432816dfe69de2724afec5db17e467c","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"166c6edea38e95694184ae6cad1d92ceba07553a","name":"Solid Security Basic <= 9.0.0 - Unauthenticated Login Page Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/solid-security-basic-900-unauthenticated-login-page-disclosure","description":"The Solid Security \u2013 Password, Two Factor Authentication, and Brute Force Protection plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 9.0.0. This is due to the plugin disclosing the login path when comments are enabled and registration is required. This makes it possible for unauthenticated attackers to discover the login page path and bypass the intended functionality of the security mechanism.","date":"2023-10-31"}],"impact":[]},{"uuid":"8f329652574bbdc5cc457b1efbb1ea426cf2b4eef1e9b2358a5ed9a84b7e7821","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"cec03e25a29a7e7f3705f209bc9213e9d1af432a","name":"WordPress  Solid Security Plugin  <= 9.0.0 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-solid-security-basic-plugin-9-0-0-unauthenticated-login-page-disclosure-vulnerability","description":"Update the WordPress Better WP Security plugin to the latest available version (at least 9.0.1).\nNaveen Muthusamy discovered and reported this Sensitive Data Exposure vulnerability in WordPress Solid Security Plugin.  This vulnerability has been fixed in version 9.0.1.","date":"2023-11-01"}],"impact":[]},{"uuid":"8e9a2b08f668b89b7ce79ca1cc361e1b5e052bf425409d80eaf1a89ebcd012fa","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b7201fc1-d825-484f-aca9-ba14a968179b","name":"Solid Security Basic &lt; 9.0.1 - Unauthenticated Login Page Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/b7201fc1-d825-484f-aca9-ba14a968179b","description":"The plugin is vulnerable to protection mechanism bypass due to disclosing the login path when comments are enabled and registration is required. This makes it possible for unauthenticated attackers to discover the login page path and bypass the intended functionality of the security mechanism.","date":null}],"impact":[]},{"uuid":"fd29ad4323e75928d095f9afd339be04049f9aa54caeb5ce3f0397942cd20223","name":"Kadence Security \u2013 Password, Two Factor Authentication, and Brute Force Protection [better-wp-security] < 9.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-44593","name":"CVE-2022-44593","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-44593","description":"[en] Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n\/a through 9.3.1.","date":"2024-06-21"},{"id":"04872cfce040d541058a50530bc87c8cfe4ffe92","name":"WordPress Solid Security Plugin <= 9.3.1 is vulnerable to Denial of Service Attack","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/better-wp-security\/vulnerability\/wordpress-solid-security-plugin-9-3-1-ip-spoofing-leading-to-denial-of-service-vulnerability","description":"<p>WordPress Solid Security Plugin <= 9.3.1 is vulnerable to Denial of Service Attack<\/p><p>Software: Solid Security<\/p><p>Link: https:\/\/wordpress.org\/plugins\/better-wp-security\/#developers<\/p><p>Affected Version <= 9.3.1<\/p><p>Fixed in version 9.3.2 <\/p>","date":"2024-06-20"},{"id":"b82cace1784cd672a8b1471cfc98c7b3110dd4fe","name":"Solid Security <= 9.3.1 - IP Address Spoofing to Denial of Service","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/better-wp-security\/solid-security-931-ip-address-spoofing-to-denial-of-service","description":"The Solid Security \u2013 Password, Two Factor Authentication, and Brute Force Protection plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 9.3.1 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to perform a denial of service attack.","date":"2024-06-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"n","i":"n","a":"l","score":"3.7","severity":"l","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","score":"3.7","severity":"low","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"none","i":"none","a":"low","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-348","name":"Use of Less Trusted Source","description":"The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1776153795"}