ithemes CVE Vulnerabilities & Metrics

Focus on ithemes vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About ithemes Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with ithemes. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total ithemes CVEs: 21
Earliest CVE date: 02 Apr 2013, 12:09 UTC
Latest CVE date: 13 Mar 2023, 14:15 UTC

Latest CVE reference: CVE-2022-31474

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical ithemes CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.64

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 2
4.0-6.9 19
7.0-8.9 4
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS ithemes CVEs

These are the five CVEs with the highest CVSS scores for ithemes, sorted by severity first and recency.

All CVEs for ithemes

CVE-2022-31474 ithemes vulnerability CVSS: 0 13 Mar 2023, 14:15 UTC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.

CVE-2022-4897 ithemes vulnerability CVSS: 0 21 Feb 2023, 09:15 UTC

The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting

CVE-2020-36176 ithemes vulnerability CVSS: 5.0 06 Jan 2021, 15:15 UTC

The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.

CVE-2020-14092 ithemes vulnerability CVSS: 7.5 02 Jul 2020, 16:15 UTC

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

CVE-2015-9379 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 13:15 UTC

iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9378 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 13:15 UTC

iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9377 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 13:15 UTC

iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9376 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 13:15 UTC

iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9375 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 13:15 UTC

Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9374 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 13:15 UTC

Stripe Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9372 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 13:15 UTC

Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9371 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 13:15 UTC

Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9370 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 13:15 UTC

Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9369 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 13:15 UTC

Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9368 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 12:15 UTC

Easy EU Value Added (VAT) Taxes Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9367 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 12:15 UTC

Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9366 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 12:15 UTC

Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9365 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 12:15 UTC

Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2015-9363 ithemes vulnerability CVSS: 4.3 28 Aug 2019, 12:15 UTC

iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVE-2018-12636 ithemes vulnerability CVSS: 6.5 22 Jun 2018, 16:29 UTC

The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.

CVE-2018-7433 ithemes vulnerability CVSS: 5.0 02 Mar 2018, 20:29 UTC

The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.

CVE-2013-2744 ithemes vulnerability CVSS: 5.0 02 Apr 2013, 12:09 UTC

importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.

CVE-2013-2743 ithemes vulnerability CVSS: 7.5 02 Apr 2013, 12:09 UTC

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.

CVE-2013-2742 ithemes vulnerability CVSS: 7.5 02 Apr 2013, 12:09 UTC

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a restore operation, which makes it easier for remote attackers to obtain access via subsequent requests to this script.

CVE-2013-2741 ithemes vulnerability CVSS: 7.5 02 Apr 2013, 12:09 UTC

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request.