Stored Cross-Site Scripting Vulnerability in Shield Security Plugin for WordPress
CVE-2023-0992
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 June 2023
What is CVE-2023-0992?
The Shield Security plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit stored Cross-Site Scripting (XSS) by manipulating the 'User-Agent' header. This flaw can result in arbitrary scripts being injected into web pages, posing a significant risk, as these scripts may execute when users access the affected pages. The vulnerability affects all versions of the plugin up to and including 17.0.17, emphasizing the importance of updating to a secure version to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Shield Security β Smart Bot Blocking & Intrusion Prevention * < 17.0.18
References
EPSS Score
34% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved