CVE-2020-36176: Ithemes Security

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.

Affected products

  • Ithemes Ithemes Security: before 7.7.0 (fixed in 7.7.0)

Published 2021-01-06. Last modified 2026-06-17.