PT-2023-16672 · WordPress · Shield Security

Ram

+1

·

Publicado

2023-06-09

·

Atualizado

2023-06-15

·

CVE-2023-0993

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shield Security plugin for WordPress versions up to, and including, 17.0.17
Description The issue concerns missing authorization on the 'theme-plugin-file' AJAX action. This allows authenticated attackers to add arbitrary audit log entries, indicating that a theme or plugin has been edited. It also serves as a vector for Cross-Site Scripting.
Recommendations For Shield Security plugin for WordPress versions up to, and including, 17.0.17, update to a version later than 17.0.17 to resolve the issue. As a temporary workaround, consider restricting access to the 'theme-plugin-file' AJAX action to minimize the risk of exploitation.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-0993

Produtos afetados

Shield Security