Vulnerability Bulletins

iThemes Security < 7.9.1 – Hide Backend ByPass


System information

   
Affected software Wordpress

Description

iThemes Security is a know security plugin in the WordPress community since years. One week ago we discovered a security issue in their “Hide Backend” module, leaking the hidden login page. This ByPass Vulnerability has been patched in 7.9.1, update it if you’re using it. ITS (iThemes Security) < 7.9.1 suffers of a GET/POST/REQUEST bug […]

More info:

https://secupress.me/blog/ithemes-security-7-9-1-hide-backend-bypass/

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2021-04-27
Ministerio de Defensa
CNI
CCN
CCN-CERT