← Back

Security

security

Vendor: Ithemes • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ithemes
1Security
Nov 21, 2024
Jun 22, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
1Ithemes
1Security
Jun 17, 2026
Mar 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.