This page lists publicly disclosed CVE vulnerabilities affecting ithemes security (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2018-12636 | The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page. | [email protected] | 7.2 | 30.85% | 2018-06-22 | 2024-11-21 |
| CVE-2018-7433 | The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page. | [email protected] | 7.5 | 1.43% | 2018-03-02 | 2024-11-21 |