WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Kadence Security – Password, Two Factor Authentication, and Brute Force Protection

Harden your site security with Login Security, Two-Factor Authentication (2FA), Vulnerability Scanner, Firewall, and more. Formerly iThemes Security.

19Reported vulnerabilities
8.3Highest CVSS score
10.0.3Latest version
700,000+Active installs

What to do now

Update Kadence Security – Password, Two Factor Authentication, and Brute Force Protection to 9.3.2 or later. 19 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 27, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2018-12636 High 7.2 29.8% Before 7.0.3 7.0.3 June 22, 2018
WF-5f7014fc-a502-4f72-899f-c21d3ca5e5b3 High 8.3 Before 3.6.4 3.6.4 August 1, 2014
CVE-2020-36176 High 7.5 1.3% Before 7.7.0 7.7.0 January 6, 2021
CVE-2018-7433 High 7.5 1.4% 6.9.0 and earlier 6.9.1 March 2, 2018
CVE-2012-4263 High 7.2 2.1% Before 3.2.5 3.2.5 May 11, 2012
WF-246eea09-abe5-41e9-811e-5cddedbbe01e High 7.4 Before 5.3.6 5.3.6 April 25, 2016
WF-1ec45848-33b1-4088-ba06-9a12d291120e High 7.2 3.5.3 and earlier 3.5.4 August 1, 2014
CVE-2012-4264 Medium 6.1 1.7% 3.2.4 and earlier 3.2.5 May 11, 2012
WF-c6168ee5-5df3-4d79-96bb-95029f2ac54b Medium 6.5 Before 4.6.13 4.6.13 April 14, 2015
WF-d2137662-d328-4da7-986a-341ff1bdca63 Medium 6.5 Before 3.4.4 3.4.4 August 20, 2012
WF-8657003f-da37-4169-9f00-262d7f3d9a9c Medium 6.4 Before 5.6.2 5.6.2 October 6, 2016
WF-f3e74fb9-edb5-4602-9aac-375701a82f84 Medium 6.4 3.6.3 and earlier 3.6.4 August 1, 2014
CVE-2022-44593 Medium 5.3 0.3% 9.3.1 and earlier 9.3.2 June 20, 2024
WF-88163d55-ab97-4697-a25b-d54615e2a843 Medium 5.3 9.0.0 and earlier 9.0.1 October 31, 2023
WF-21a1a6c2-0eb1-4ee3-abf0-76b84adca01b Medium 5.3 Before 7.9.1 7.9.1 April 22, 2021
WF-0a49c8df-0524-41af-b095-b5953e6f68d8 Medium 5.3 5.6.1 and earlier 5.6.2 September 27, 2016
WF-32d0f709-192a-4d9f-bfe9-15c1be4c4b95 Medium 5.3 Before 5.3.1 5.3.1 April 21, 2016
CVE-2023-28786 Medium 4.7 0.4% 8.1.4 and earlier 8.1.5 March 27, 2023
WF-e9f0689d-aa35-4dfb-b264-5d7378ab1a54 Low 3.3 Before 5.3.5 5.3.5 April 5, 2016

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.