iThemes Security <= 7.6.1 - Broken Password Mechanism

2021-01-06 00:00
Anonymous

Vulnerability Overview

The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.

Technical Analysis

REMEDIATION: Update to version 7.7.0, or a newer patched version --- IDENTIFIER: CWE-286 (Incorrect User Management) The product does not properly manage a user within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C