PT-2023-16672 · WordPress · Shield Security
Ram
+1
·
Published
2023-06-09
·
Updated
2023-06-15
·
CVE-2023-0993
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Shield Security plugin for WordPress versions up to, and including, 17.0.17
Description
The issue concerns missing authorization on the 'theme-plugin-file' AJAX action. This allows authenticated attackers to add arbitrary audit log entries, indicating that a theme or plugin has been edited. It also serves as a vector for Cross-Site Scripting.
Recommendations
For Shield Security plugin for WordPress versions up to, and including, 17.0.17, update to a version later than 17.0.17 to resolve the issue. As a temporary workaround, consider restricting access to the 'theme-plugin-file' AJAX action to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shield Security