CVE-2018-12636: SQL Injection
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12636?
CVE-2018-12636 is a vulnerability in the iThemes Security (better-wp-security) plugin before version 7.0.3 for WordPress that allows SQL Injection by attackers with Admin privileges via the logs page.
How severe is CVE-2018-12636?
CVE-2018-12636 has a severity rating of high, with a severity value of 7.2.
How does CVE-2018-12636 affect the iThemes Security plugin?
CVE-2018-12636 affects the iThemes Security (better-wp-security) plugin before version 7.0.3 for WordPress.
How can the SQL Injection vulnerability be exploited?
The SQL Injection vulnerability in CVE-2018-12636 can be exploited by attackers with Admin privileges via the logs page.
How can I fix CVE-2018-12636?
To fix CVE-2018-12636, update the iThemes Security (better-wp-security) plugin to version 7.0.3 or later.