CVE-2020-36176: High severity ithemes security vulnerability
Published Jan 6, 2021
·Updated
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.
Affected Software
1 affected component
iThemes Ithemes Security Wordpress<7.7.0
Event History
Jan 6, 2021
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-36176.
2
What is the severity of CVE-2020-36176?
The severity of CVE-2020-36176 is high with a CVSS score of 7.5.
3
What is the affected software version for CVE-2020-36176?
The affected software version for CVE-2020-36176 is iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress.
4
What is the impact of CVE-2020-36176?
CVE-2020-36176 allows an attacker to bypass the new-password requirement for an existing account until the second login occurs.
5
How can I fix CVE-2020-36176?
To fix CVE-2020-36176, update the iThemes Security plugin to version 7.7.0 or later.