Extension WordPress
Vulnérabilités Kadence Security – Password, Two Factor Authentication, and Brute Force Protection
Cette page rassemble les failles publiées pour Kadence Security – Password, Two Factor Authentication, and Brute Force Protection, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Kadence Security – Password, Two Factor Authentication, and Brute Force Protection
19 fiches
Solid Security <= 9.3.1 – IP Address Spoofing to Denial of Service
The Solid Security – Password, Two Factor Authentication, and Brute Force Protection plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 9.3.1 due to insufficient IP address validation. This makes it…
*-9.3.1
9.3.2
20/06/2024
Solid Security Basic <= 9.0.0 – Unauthenticated Login Page Disclosure
The Solid Security – Password, Two Factor Authentication, and Brute Force Protection plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 9.0.0. This is due to the plugin disclosing the login…
*-9.0.0
9.0.1
31/10/2023
iThemes Security <= 8.1.4 – Open Redirection via redirect_to_https
The iThemes Security plugin for WordPress is vulnerable to open redirection in versions up to, and including, 8.1.4. This is due to the use of wp_redirect instead of wp_safe_redirect in the redirect_to_https function. This makes it possible for…
*-8.1.4
8.1.5
27/03/2023
iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 – Hidden Login Bypass
It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4
[*, 7.9.1)
7.9.1
22/04/2021
iThemes Security <= 7.6.1 – Broken Password Mechanism
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.
*-7.6.1
7.7.0
06/01/2021
iThemes Security <= 7.0.2 – Authenticated SQL Injection
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
[*, 7.0.3)
7.0.3
25/06/2018
iThemes Security <= 6.9.0 – Cross-Site Scripting
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
*-6.9.0
6.9.1
05/03/2018
iThemes Security <= 5.6.1 – Stored Cross-Site Scripting
The iThemes Security for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject…
[*, 5.6.2)
5.6.2
06/10/2016
iThemes Security <= 5.6.1 – Sensitive Information Exposure via Diff Response
The iThemes Security plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including 5.6.1, due to invalid username/password combinations returning different HTTP headers on response. This makes it possible for attackers to observe…
*-5.6.1
5.6.2
27/09/2016
iThemes Security <= 5.3.5 – Missing Capabilities Check
The iThemes Security plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_itsec_file_change_warning_ajax function in versions up to, and including, 5.3.5. This makes it possible for authenticated attackers to perform administrative…
[*, 5.3.6)
5.3.6
25/04/2016
iThemes Security < 5.3.1 – Insecure Backup/Logfile Generation
The iThemes Security plugin for WordPress is vulnerable to insecure backup and logfile generation in versions up to, and including, 5.3.0. This is due to backup and logfiles being created in a world-readable directory. This makes it possible…
[*, 5.3.1)
5.3.1
21/04/2016
iThemes Security < 5.3.5 – Authenticated Cross-Site Scripting
The iThemes Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts…
[*, 5.3.5)
5.3.5
05/04/2016
iThemes Security <= 4.6.12 – Stored Cross-Site Scripting
The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.6.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject…
[*, 4.6.13)
4.6.13
14/04/2015
Better WP Security <= 3.6.3 – Stored Cross-Site Scripting
The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-3.6.3
3.6.4
01/08/2014
iThemes Security < 3.6.4 – Stored Cross-Site Scripting
The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter in versions before 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web…
[*, 3.6.4)
3.6.4
01/08/2014
Better WP Security <= 3.5.3 – Stored Cross-Site Scripting
The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inc/secure.php' file in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping on logged data. This makes it…
*-3.5.3
3.5.4
01/08/2014
iThemes Security < 3.4.4 – Cross-Site Scripting
The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
[*, 3.4.4)
3.4.4
20/08/2012
Better WP Security <= 3.2.4 – Multiple Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263.
*-3.2.4
3.2.5
11/05/2012
iThemes Security < 3.2.5 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (iThemes) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.
[*, 3.2.5)
3.2.5
11/05/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.