Reflected Cross-Site Scripting Vulnerability in Shield Security Plugin for WordPress
CVE-2026-0561

6.1MEDIUM

What is CVE-2026-0561?

The Shield Security plugin for WordPress is susceptible to Reflected Cross-Site Scripting due to inadequate input sanitization in the 'message' parameter across all versions up to and including 21.0.8. This flaw allows unauthenticated attackers to craft malicious web scripts that may execute in the user's browser if they can convince the user to interact with a specially crafted link, leading to potential compromise of user data and unauthorized actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Shield: Blocks Bots, Protects Users, and Prevents Security Breaches * <= 21.0.8

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.