7.2
CVSSv3

CVE-2018-12636

Published: 22/06/2018 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The iThemes Security (better-wp-security) plugin prior to 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ithemes security

Exploits

# Exploit Title: WordPress Plugin iThemes Security(better-wp-security) <= 702 - Authenticated SQL Injection # Date: 2018-06-25 # Exploit Author: Çlirim Emini # Website: wwwsentrycocom/ # Vendor Homepage: ithemescom/ # Software Link: wordpressorg/plugins/better-wp-security/ # Version/s: 702 and below # Patched V ...