CVE Database /
CVE-2023-6989
CVE · Critical
CVE-2023-6989 — Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 18.5.10
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-6989
|
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 18.5.10 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Critical
9.8
|
< 18.5.10
|
18.5.10 |
2024-02-05 |
—
|
CVE-2023-6989
The Shield Security plugin for WordPress is vulnerable to local file inclusion in versions before 18.5.10, a flaw discovered by hir0ot that permits attackers to read and display arbitrary files from the affected website. This vulnerability poses a significant risk if sensitive files containing credentials, including database access details, are exposed, potentially enabling complete database compromise. The vulnerability has been resolved in version 18.5.10 and users should update to this version or later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings