Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ithemes vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2015-9374
Stripe Add-on for iThemes Exchange prior to 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Stripe
NA
CVE-2022-4897
The BackupBuddy WordPress plugin prior to 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting
Ithemes Backupbuddy
5
CVSSv2
CVE-2018-7433
The iThemes Security plugin prior to 6.9.1 for WordPress does not properly perform data escaping for the logs page.
Ithemes Security
6.5
CVSSv2
CVE-2018-12636
The iThemes Security (better-wp-security) plugin prior to 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
Ithemes Security
1 EDB exploit
4.3
CVSSv2
CVE-2015-9364
2Checkout Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
2checkout Ithemes 2checkout
4.3
CVSSv2
CVE-2015-9371
Manual Purchases Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Manual Purchases
5
CVSSv2
CVE-2013-2744
importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote malicious users to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.
Ithemes Backupbuddy 2.2.25
7.5
CVSSv2
CVE-2020-14092
The CodePeople Payment Form for PayPal Pro plugin prior to 1.1.65 for WordPress allows SQL Injection.
Ithemes Paypal Pro
4.3
CVSSv2
CVE-2015-9375
Table Rate Shipping Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Table Rate Shipping
4.3
CVSSv2
CVE-2015-9377
iThemes Builder Theme Depot prior to 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Builder Theme Depot
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3201
CVE-2024-4779
CVE-2024-35090
CVE-2024-5084
hard-coded
CVE-2024-4985
HTML injection
CVE-2024-33655
local file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »