Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ithemes vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2015-9376
iThemes Mobile prior to 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Mobile
655
VMScore
CVE-2018-12636
The iThemes Security (better-wp-security) plugin prior to 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
Ithemes Security
1 EDB exploit
NA
CVE-2022-4897
The BackupBuddy WordPress plugin prior to 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting
Ithemes Backupbuddy
383
VMScore
CVE-2015-9372
Membership Add-on for iThemes Exchange prior to 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Membership
668
VMScore
CVE-2020-14092
The CodePeople Payment Form for PayPal Pro plugin prior to 1.1.65 for WordPress allows SQL Injection.
Ithemes Paypal Pro
383
VMScore
CVE-2015-9364
2Checkout Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
2checkout Ithemes 2checkout
383
VMScore
CVE-2015-9371
Manual Purchases Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Manual Purchases
445
VMScore
CVE-2013-2744
importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote malicious users to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.
Ithemes Backupbuddy 2.2.25
383
VMScore
CVE-2015-9373
PayPal Pro Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Webdevstudios Ithemes Paypal Pro
383
VMScore
CVE-2015-9377
iThemes Builder Theme Depot prior to 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Builder Theme Depot
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »