Description
WordPress Plugin iThemes Security (formerly Better WP Security) is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently hide file changes notifications from administrator. WordPress Plugin iThemes Security (formerly Better WP Security) version 5.3.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.3.6 or latest
References
Related Vulnerabilities
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block SQL Injection (2.5.24)
PHP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2022-31628)
WordPress Plugin Gallery-Flagallery Photo Portfolio 'skin' Parameter Cross-Site Scripting (1.72)
WordPress Plugin SoundCloud Is Gold Cross-Site Scripting (2.3.1)
WordPress Plugin Upload File Type Settings Cross-Site Scripting (1.1)