[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5QDM8EJgSzqLyIjHYqMFQ7fldCuNzh3Nn7imoGj4Eu8":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20},"WF-8657003f-da37-4169-9f00-262d7f3d9a9c-better-wp-security","ithemes-security-stored-cross-site-scripting-2","iThemes Security \u003C= 5.6.1 - Stored Cross-Site Scripting","The iThemes Security for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.\r\n\r\n\"Security Fix: Updated log output to prevent specific kinds of logged requests from displaying without sanitization. Thanks to Slavco Mihajloski for contacting us about this issue.\" ~ https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbetter-wp-security\u002F#developers","better-wp-security",null,"\u003C5.6.2","5.6.2","medium",6.4,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2016-10-06 00:00:00","2024-01-22 19:56:02",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F8657003f-da37-4169-9f00-262d7f3d9a9c?source=api-prod",2665]