CVE Database /
CVE-2023-0993
CVE · Medium
CVE-2023-0993 — Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 17.0.18
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-0993
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 17.0.18 |
Missing Authorization |
Medium
4.3
|
< 17.0.18
|
17.0.18 |
2023-04-25 |
—
|
CVE-2023-0993
The Shield Security plugin for WordPress contains an authorization flaw in the 'theme-plugin-file' AJAX action affecting versions 17.0.17 and earlier. Authenticated users can exploit this vulnerability to inject false audit log entries claiming that themes or plugins were modified, and it also serves as a potential attack vector for cross-site scripting issues as documented in CVE-2023-0992. The vulnerability was remedied in version 17.0.18.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings