CVE-2018-12636: Ithemes Security

High severity, CVSS 7.2. EPSS: 29.8% chance of exploitation in the next 30 days.

The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.

Affected products

  • Ithemes Security: before 7.0.3 (fixed in 7.0.3)

Published 2018-06-22. Last modified 2026-06-17.