iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass
Strategic Overview
- Status
- Patched in 7.9.1
- Affected Version
< 7.9.1- CVSS
- 5.3Medium
- Weakness type
- CWE-693 · Protection Mechanism Failure
- CVE
CVE pending
At a glance
This record tracks a medium-severity Protection Mechanism Failure vulnerability in the Kadence Security WordPress plugin, affecting versions < 7.9.1. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 7.9.1; sites on affected versions should update now. Disclosed April 2021, reported by Julio Potier.
Vulnerability Overview
It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-693: Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Remediation
Update to version 7.9.1, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: Kadence Security 7.9.1 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Same weakness class
Other vulnerabilities in Kadence Security – Password, Two Factor Authentication, and Brute Force Protection
- 8.3iThemes Security < 3.6.4 Stored Cross-Site Scripting
- 7.5CVE-2020-36176: iThemes Security <= 7.6.1 Broken Password Mechanism
CVE-2020-36176 - 7.5CVE-2018-7433: iThemes Security <= 6.9.0 Cross-Site Scripting
CVE-2018-7433 - 7.4iThemes Security <= 5.3.5 Missing Capabilities Check
- 7.2CVE-2018-12636: iThemes Security <= 7.0.2 SQL Injection
CVE-2018-12636 - 7.2Better WP Security <= 3.5.3 Stored Cross-Site Scripting
- 7.2CVE-2012-4263: iThemes Security < 3.2.5 Cross-Site Scripting
CVE-2012-4263 - 6.5iThemes Security <= 4.6.12 Stored Cross-Site Scripting
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C