{"error":0,"message":null,"data":{"name":"iThemes Security Pro","plugin":"ithemes-security-pro","link":null,"latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"9f21125097ed9f6cc74d7dd4e5cff6f5d35e490e3065979c0f20a69983678853","name":"iThemes Security Pro [ithemes-security-pro] < 6.8.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.8.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"87dcb17fc265f28c8004d33b6fdc7c3e42180a60","name":"WordPress iThemes Security Pro premium plugin <= 6.8.3 - Hide Backend Bypass vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ithemes-security-pro\/vulnerability\/wordpress-ithemes-security-pro-premium-plugin-6-8-3-hide-backend-bypass-vulnerability","description":"Hide Backend Bypass vulnerability discovered by Julio Potier (SecuPress) in WordPress iThemes Security Pro premium plugin (versions <= 6.8.3).","date":"2021-04-21"}],"impact":[]},{"uuid":"9b0f5249afee792246773884ef4de470d40f265f0d14e17f4b66039f7c4a83ad","name":"iThemes Security Pro [ithemes-security-pro] < 6.8.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.8.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"42fdb534-3aef-4ed7-94a8-4cfe8ff977e1","name":"iThemes Security Free (&lt; 7.9.1) &amp; Pro (&lt; 6.8.4) - Hide Backend Bypass","link":"https:\/\/wpscan.com\/vulnerability\/42fdb534-3aef-4ed7-94a8-4cfe8ff977e1","description":"Both the iThemes Security free and pro versions were affected.\r\n\r\n- Patched in Version (iThemes Security): 7.9.1\r\n- Patched in Version (iThemes Security Pro): 6.8.4\r\n\r\nThe bug allowed attackers to bypass the &quot;Hide Backend&quot; feature, that, when enabled, hides the WordPress wp-login.php and wp-admin pages.\r\n\r\nThis could allow attackers to conduct brute force or other attacks against the &quot;hidden&quot; pages, giving a false sense of security.\r\n\r\nThis vulnerability was discovered and responsibly disclosed by Julio Potier of SecuPress.\r\n\r\nUpdate to version 7.9.1 of iThemes Security and 6.8.4 of iThemes Security Pro to receive the Hide Backed bypass workaround patch.","date":null}],"impact":[]},{"uuid":"8bd7e6dabf39a03f9b925a2c22ceba53f70249f3483855e38f094fb318a3e121","name":"iThemes Security Pro [ithemes-security-pro] < 6.8.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.8.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"635a923295fe04f78b5819b6f3bc0ed9a6f088a3","name":"iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/ithemes-security-791-and-ithemes-security-pro-684-hidden-login-bypass","description":"It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4","date":"2021-04-22"}],"impact":[]}]},"updated":"1671615576"}