iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass

2021-04-22 00:00
Julio Potier

Strategic Overview

Status
Patched in 7.9.1
Affected Version
< 7.9.1
CVSS
5.3Medium
Weakness type
CWE-693 · Protection Mechanism Failure
CVE
CVE pending
View all Kadence Security – Password, Two Factor Authentication, and Brute Force Protection vulnerabilities

At a glance

This record tracks a medium-severity Protection Mechanism Failure vulnerability in the Kadence Security WordPress plugin, affecting versions < 7.9.1. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 7.9.1; sites on affected versions should update now. Disclosed April 2021, reported by Julio Potier.

Vulnerability Overview

It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.

CWE-693: Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Remediation

Update to version 7.9.1, or a newer patched version

How does WordSec protect against this?

The fix is the thing that ends this: Kadence Security 7.9.1 closes this, and updating the plugin is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C