iThemes Security <= 5.3.5 - Missing Capabilities Check
2016-04-25 00:00
Julio PotierStrategic Overview
StatusPatched in 5.3.6
Affected Version
< 5.3.6CVSS7.4High
CVE
N/AVulnerability Overview
The iThemes Security plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_itsec_file_change_warning_ajax function in versions up to, and including, 5.3.5. This makes it possible for authenticated attackers to perform administrative actions.
Technical Analysis
REMEDIATION: Update to version 5.3.6, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C