Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Wp Simple Firewall — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
wp-simple-firewall
- 30000+ instalaciones activas
2FAActivity Logbotsfirewallsecurity
Estado de mantenimiento
- Última versión conocida: 22.1.3
- Requiere PHP: 7.4+
Vulnerabilidades conocidas
11 CVEs conocidos registrados para Wp Simple Firewall.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2025-14427
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 21.0.10 |
Falta de control de autorización |
Media
4,3
|
< 21.0.10
|
21.0.10 |
2026-02-18 |
✓ corregido en la última versión
|
|
CVE-2025-15370
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 21.0.10 |
Elusión de autorización mediante una clave controlada por el usuario |
Media
4,3
|
< 21.0.10
|
21.0.10 |
2026-01-15 |
✓ corregido en la última versión
|
|
CVE-2024-7313
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 20.0.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 20.0.6
|
20.0.6 |
2024-08-05 |
✓ corregido en la última versión
|
|
CVE-2024-4344
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 19.1.11 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 19.1.11
|
19.1.11 |
2024-06-01 |
✓ corregido en la última versión
|
|
CVE-2023-6989
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 18.5.10 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Crítica
9,8
|
< 18.5.10
|
18.5.10 |
2024-02-05 |
✓ corregido en la última versión
|
|
CVE-2024-22163
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 18.5.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 18.5.8
|
18.5.8 |
2024-01-16 |
✓ corregido en la última versión
|
|
CVE-2023-0992
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 17.0.18 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 17.0.18
|
17.0.18 |
2023-04-25 |
✓ corregido en la última versión
|
|
CVE-2023-0993
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 17.0.18 |
Falta de control de autorización |
Media
4,3
|
< 17.0.18
|
17.0.18 |
2023-04-25 |
✓ corregido en la última versión
|
CVE-2025-14427
The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `MfaEmailDisable` action in all versions up to, and including, 21.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable the global Email 2FA setting for the entire site.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-15370
The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 21.0.9 via the MfaGoogleAuthToggle class due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable Google Authenticator for any user.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-7313
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nav_sub' parameter in all versions up to, and including, 20.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-4344
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.1.13. This is due to missing or incorrect nonce validation on the exec function. This makes it possible for unauthenticated attackers to disable pin protection for the admin interface of the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-6989
Update the WordPress Shield Security plugin to the latest available version (at least 18.5.10).
hir0ot discovered and reported this Local File Inclusion vulnerability in WordPress Shield Security Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentially allow complete database takeover depending on the configuration. This vulnerability has been fixed in version 18.5.10.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-22163
Update the WordPress Shield Security plugin to the latest available version (at least 18.5.8).
Yudistira Arya discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shield Security Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 18.5.8.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-0992
Update the WordPress Shield Security plugin to the latest available version (at least 17.0.18).
Ramuel Gall discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shield Security Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 17.0.18.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-0993
The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action in versions up to, and including, 17.0.17. This allows authenticated attackers to add arbitrary audit log entries indicating that a theme or plugin has been edited, and is also a vector for Cross-Site Scripting via CVE-2023-0992.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
+ 3 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2022-0211
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 13.0.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 13.0.6
|
13.0.6 |
2022-01-19 |
✓ corregido en la última versión
|
|
CVE-2026-0561
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 21.0.10 |
— |
Desconocido
|
< 21.0.10
|
21.0.10 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-0722
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 21.0.10 |
— |
Desconocido
|
< 21.0.10
|
21.0.10 |
0000-00-00 |
✓ corregido en la última versión
|
CVE-2022-0211
The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-0561
The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 21.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-0722
The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired' function. This makes it possible for unauthenticated attackers to execute SQL injection attacks, extracting sensitive information from the database, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Cómo solucionarlo
Mantén Wp Simple Firewall actualizado — 22.1.3 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas