CVE Database /
CVE-2022-0211
CVE · Medium
CVE-2022-0211 — Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 13.0.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-0211
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 13.0.6 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 13.0.6
|
13.0.6 |
2022-01-19 |
—
|
CVE-2022-0211
The Shield Security plugin for WordPress versions prior to 13.0.6 fails to properly sanitize and escape administrator notes, creating a cross-site scripting vulnerability that high-privilege users can exploit even when the unfiltered_html capability is restricted.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings