High severity7.5NVD Advisory· Published Jan 6, 2021· Updated Jun 17, 2026
CVE-2020-36176
CVE-2020-36176
Description
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- iThemes Security/iThemes Securitydescription
- Range: <7.7.0
Patches
Vulnerability mechanics
References
1- wordpress.org/plugins/better-wp-security/nvdProductRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.