PT-2023-16672 · WordPress · Shield Security

Ram

+1

·

Published

2023-06-09

·

Updated

2023-06-15

·

CVE-2023-0993

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shield Security plugin for WordPress versions up to, and including, 17.0.17
Description The issue concerns missing authorization on the 'theme-plugin-file' AJAX action. This allows authenticated attackers to add arbitrary audit log entries, indicating that a theme or plugin has been edited. It also serves as a vector for Cross-Site Scripting.
Recommendations For Shield Security plugin for WordPress versions up to, and including, 17.0.17, update to a version later than 17.0.17 to resolve the issue. As a temporary workaround, consider restricting access to the 'theme-plugin-file' AJAX action to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-0993

Affected Products

Shield Security