CVE · Medium

CVE-2023-0993 — Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 17.0.18

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0993 Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 17.0.18 Missing Authorization Medium 4.3 < 17.0.18 17.0.18 2023-04-25

CVE-2023-0993

The Shield Security plugin for WordPress contains an authorization flaw in the 'theme-plugin-file' AJAX action affecting versions 17.0.17 and earlier. Authenticated users can exploit this vulnerability to inject false audit log entries claiming that themes or plugins were modified, and it also serves as a potential attack vector for cross-site scripting issues as documented in CVE-2023-0992. The vulnerability was remedied in version 17.0.18.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.