iThemes Security <= 5.6.1 - Sensitive Information Exposure via Diff Response

2016-09-27 00:00
Leon Atkinson of 18INT

Vulnerability Overview

The iThemes Security plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including 5.6.1, due to invalid username/password combinations returning different HTTP headers on response. This makes it possible for attackers to observe differences in responses to determine valid usernames on the site (username enumeration).

Technical Analysis

REMEDIATION: Update to version 5.6.2, or a newer patched version --- IDENTIFIER: CWE-204 (Observable Response Discrepancy) The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C