MEDIUM
Shield Security <= 17.0.17 - Missing Authorization
Published Jun 9, 2023
4.3
MEDIUMCVSS 3.1
EPSS 0.55%
Description
The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action in versions up to, and including, 17.0.17. This allows authenticated attackers to add arbitrary audit log entries indicating that a theme or plugin has been edited, and is also a vector for Cross-Site Scripting via CVE-2023-0992.
Affected products
- Vendor Paultgoodchild Product Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Defaultunaffected
Affected
- ≥ 0, < 17.0.18
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Paultgoodchild | Shield: Blocks Bots, Protects Users, and Prevents Security Breaches | unaffected | Affected
|
- ≤ 17.0.17
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12978 Advisory
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2883864%40wp-simple-firewall%2Ftrunk&old=2883536%40wp-simple-firewall%2Ftrunk&sfp_email=&sfph_mail= Patch
- https://wordpress.org/plugins/wp-simple-firewall/ Product
- https://www.wordfence.com/blog/2023/04/multiple-vulnerabilities-patched-in-shield-security/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/674461ad-9b61-48c4-af2a-5dfcaeb38215?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Jun 9, 2023
Updated Apr 8, 2026
Reserved Feb 23, 2023
Link CVE-2023-0993
CISA Vulnrichment
Updated Nov 23, 2024
Red Hat
No data
GitHub
No data