Loading product vulnerabilities…
Total
2
Critical
0
High
0
Medium
0
CISA KEV
0
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.