CVE · Critical

CVE-2023-6989 — Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 18.5.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6989 Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 18.5.10 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.8 < 18.5.10 18.5.10 2024-02-05

CVE-2023-6989

The Shield Security plugin for WordPress is vulnerable to local file inclusion in versions before 18.5.10, a flaw discovered by hir0ot that permits attackers to read and display arbitrary files from the affected website. This vulnerability poses a significant risk if sensitive files containing credentials, including database access details, are exposed, potentially enabling complete database compromise. The vulnerability has been resolved in version 18.5.10 and users should update to this version or later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.