PT-2023-8522 · WordPress · The Shield Security

Hir0Ot

+1

·

Published

2023-12-18

·

Updated

2024-02-28

·

CVE-2023-6989

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress versions up to, and including, 18.5.9
Description The issue is related to Local File Inclusion, which allows an unauthenticated attacker to include and execute PHP files on the server via the render action template parameter. This enables the execution of any PHP code in those files. The vulnerability is associated with incorrect external control of the file name or path. It is estimated that over 50,000 sites are affected.
Recommendations For versions up to, and including, 18.5.9, update to a version that fixes this issue. As a temporary workaround, consider disabling the render action template parameter until a patch is available. Restrict access to the setTemplate(), renderPhp(), and path join() functions to minimize the risk of exploitation. Avoid using the render action template parameter in the affected plugin until the issue is resolved.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-01090
CVE-2023-6989

Affected Products

The Shield Security