Stored Cross-Site Scripting Vulnerability in Shield Security Plugin for WordPress
CVE-2023-0992
6.1MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 June 2023
What is CVE-2023-0992?
The Shield Security plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit stored Cross-Site Scripting (XSS) by manipulating the 'User-Agent' header. This flaw can result in arbitrary scripts being injected into web pages, posing a significant risk, as these scripts may execute when users access the affected pages. The vulnerability affects all versions of the plugin up to and including 17.0.17, emphasizing the importance of updating to a secure version to mitigate potential threats.
Affected Version(s)
Shield Security – Smart Bot Blocking & Intrusion Prevention * < 17.0.18
References
EPSS Score
34% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ramuel Gall