Data Modification Vulnerability in Shield Security Plugin for WordPress
CVE-2025-14427

4.3MEDIUM

What is CVE-2025-14427?

The Shield Security plugin for WordPress has a vulnerability that allows authenticated attackers with Subscriber-level access and above to disable the global Email 2FA setting for the entire site. This occurs due to a missing capability check on the MfaEmailDisable action in all versions up to and including 21.0.9. As a result, this flaw can potentially lead to unauthorized modifications of site security settings, making it crucial for website administrators to patch and update their plugins promptly to maintain the integrity of their security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Shield: Blocks Bots, Protects Users, and Prevents Security Breaches * <= 21.0.9

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Angus Girvan
.