1 results (0.000 seconds)
CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0
CVE-2020-36176 – iThemes Security <= 7.6.1 - Broken Password Mechanism
https://notcve.org/view.php?id=CVE-2020-36176
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs. El plugin iThemes Security (anteriormente Better WP Security) versiones anteriores a 7.7.0 para WordPress, no aplica el requisito de una nueva contraseña para una cuenta existente hasta que el segundo inicio de sesión ocurre • https://wordpress.org/plugins/better-wp-security/#developers • CWE-286: Incorrect User Management CWE-287: Improper Authentication •