Stored Cross-Site Scripting Vulnerability in Shield Security Plugin for WordPress
CVE-2023-0992
6.1MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 9 June 2023
Summary
The Shield Security plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit stored Cross-Site Scripting (XSS) by manipulating the 'User-Agent' header. This flaw can result in arbitrary scripts being injected into web pages, posing a significant risk, as these scripts may execute when users access the affected pages. The vulnerability affects all versions of the plugin up to and including 17.0.17, emphasizing the importance of updating to a secure version to mitigate potential threats.
Affected Version(s)
Shield Security – Smart Bot Blocking & Intrusion Prevention * < 17.0.18
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ramuel Gall