Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ithemes vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2015-9374
Stripe Add-on for iThemes Exchange prior to 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Stripe
6.1
CVSSv3
CVE-2022-4897
The BackupBuddy WordPress plugin prior to 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting
Ithemes Backupbuddy
7.5
CVSSv3
CVE-2018-7433
The iThemes Security plugin prior to 6.9.1 for WordPress does not properly perform data escaping for the logs page.
Ithemes Security
7.2
CVSSv3
CVE-2018-12636
The iThemes Security (better-wp-security) plugin prior to 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
Ithemes Security
1 EDB exploit
6.1
CVSSv3
CVE-2015-9364
2Checkout Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
2checkout Ithemes 2checkout
6.1
CVSSv3
CVE-2015-9371
Manual Purchases Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Manual Purchases
NA
CVE-2013-2744
importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote malicious users to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.
Ithemes Backupbuddy 2.2.25
9.8
CVSSv3
CVE-2020-14092
The CodePeople Payment Form for PayPal Pro plugin prior to 1.1.65 for WordPress allows SQL Injection.
Ithemes Paypal Pro
6.1
CVSSv3
CVE-2015-9375
Table Rate Shipping Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Table Rate Shipping
6.1
CVSSv3
CVE-2015-9377
iThemes Builder Theme Depot prior to 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Builder Theme Depot
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
spoof
CVE-2024-34928
CVE-2024-5291
deserialization
CVE-2024-4471
CVE-2024-4956
CVE-2024-32002
CVE-2024-5227
unspecified
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »