iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4 - Hidden Login Bypass

2021-04-22 00:00
Julio Potier

Vulnerability Overview

It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.4

Technical Analysis

REMEDIATION: Update to version 7.9.1, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C