[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVVfYi-ZWyqa7YL6yDovw9PcoYvPzVNjbfPiEurWoFWg":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20},"WF-0a49c8df-0524-41af-b095-b5953e6f68d8-better-wp-security","ithemes-security-sensitive-information-exposure-via-diff-response","iThemes Security \u003C= 5.6.1 - Sensitive Information Exposure via Diff Response","The iThemes Security plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including 5.6.1, due to invalid username\u002Fpassword combinations returning different HTTP headers on response. This makes it possible for attackers to observe differences in responses to determine valid usernames on the site (username enumeration).","better-wp-security",null,"\u003C=5.6.1","5.6.2","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Observable Response Discrepancy","2016-09-27 00:00:00","2024-01-22 19:56:02",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F0a49c8df-0524-41af-b095-b5953e6f68d8?source=api-prod",2674]