PT-2026-20628 · WordPress · Shield Security
Dmitry Ignatyev
·
Published
2026-02-19
·
Updated
2026-02-19
·
CVE-2026-0722
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Shield Security plugin for WordPress versions prior to 21.0.9
Description
The Shield Security plugin for WordPress is susceptible to Cross-Site Request Forgery. This occurs because the plugin does not properly verify nonces, specifically allowing bypass via a user-supplied parameter in the
isNonceVerifyRequired() function. This enables unauthenticated attackers to potentially execute SQL injection attacks and extract sensitive information from the database through a forged request, provided they can trick a site administrator into performing an action.Recommendations
Update the Shield Security plugin to version 21.0.9 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shield Security