Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ithemes vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2015-9370
Invoices Add-on for iThemes Exchange prior to 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Invoices
6.1
CVSSv3
CVE-2015-9372
Membership Add-on for iThemes Exchange prior to 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Membership
6.1
CVSSv3
CVE-2015-9376
iThemes Mobile prior to 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Mobile
7.2
CVSSv3
CVE-2018-12636
The iThemes Security (better-wp-security) plugin prior to 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
Ithemes Security
1 EDB exploit
NA
CVE-2013-2744
importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote malicious users to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.
Ithemes Backupbuddy 2.2.25
6.1
CVSSv3
CVE-2015-9364
2Checkout Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
2checkout Ithemes 2checkout
6.1
CVSSv3
CVE-2015-9371
Manual Purchases Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Manual Purchases
9.8
CVSSv3
CVE-2020-14092
The CodePeople Payment Form for PayPal Pro plugin prior to 1.1.65 for WordPress allows SQL Injection.
Ithemes Paypal Pro
6.1
CVSSv3
CVE-2015-9366
Custom URL Tracking Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Ithemes Custom Url Tracking
6.1
CVSSv3
CVE-2015-9373
PayPal Pro Add-on for iThemes Exchange prior to 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Webdevstudios Ithemes Paypal Pro
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
CVE-2006-4304
CVE-2023-26603
CVE-2024-28327
CVE-2023-50363
CVE-2024-21905
template injection
CVE-2024-3400
cross-site request forgery
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »