Extension WordPress

Vulnérabilités Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Cette page rassemble les failles publiées pour Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
1Critiques
11Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

11 fiches

CVE-2026-0722 Moyenne · 6,5
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Shield Security <= 21.0.8 – Cross-Site Request Forgery to SQL Injection

The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired'…

Versions affectées

*-21.0.8

Correctif

21.0.10

Publication

18/02/2026

CVE-2026-0561 Moyenne · 6,1
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Shield Security <= 21.0.8 – Unauthenticated Reflected Cross-Site Scripting via 'message' Parameter

The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 21.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-21.0.8

Correctif

21.0.10

Publication

18/02/2026

CVE-2025-14427 Moyenne · 4,3
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches <= 21.0.9 – Missing Authorization to Authenticated (Subscriber+) Email MFA Update

The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `MfaEmailDisable` action in all versions up to, and including,…

Versions affectées

*-21.0.9

Correctif

21.0.10

Publication

18/02/2026

CVE-2025-15370 Moyenne · 4,3
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Shield Security <= 21.0.9 – Authenticated (Subscriber+) Insecure Direct Object Reference to Disable Google Authenticator

The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 21.0.9 via the MfaGoogleAuthToggle class due to missing validation on a…

Versions affectées

*-21.0.9

Correctif

21.0.10

Publication

15/01/2026

CVE-2024-7313 Moyenne · 6,1
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 20.0.5 – Reflected Cross-Site Scripting

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nav_sub' parameter in all versions up to, and including, 20.0.5 due to insufficient input sanitization and…

Versions affectées

*-20.0.5

Correctif

20.0.6

Publication

05/08/2024

CVE-2024-4344 Moyenne · 4,3
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 19.1.13 – Cross-Site Request Forgery

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.1.13. This is due to missing or incorrect nonce validation on…

Versions affectées

*-19.1.10

Correctif

19.1.11

Publication

01/06/2024

CVE-2023-6989 Critique · 9,8
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 – Unauthenticated Local File Inclusion

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated…

Versions affectées

*-18.5.9

Correctif

18.5.10

Publication

05/02/2024

CVE-2024-22163 Élevée · 7,2
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Shield Security <= 18.5.7 – Unauthenticated Stored Cross-Site Scripting via getColumnContent_Page

The Shield Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the getColumnContent_Page function in versions up to, and including, 18.5.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-18.5.7

Correctif

18.5.8

Publication

16/01/2024

CVE-2023-0993 Moyenne · 4,3
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Shield Security <= 17.0.17 – Missing Authorization

The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action in versions up to, and including, 17.0.17. This allows authenticated attackers to add arbitrary audit log entries indicating that a theme or…

Versions affectées

[*, 17.0.18)

Correctif

17.0.18

Publication

25/04/2023

CVE-2023-0992 Élevée · 7,2
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning

Shield Security <= 17.0.17 – Unauthenticated Stored Cross-Site Scripting

The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…

Versions affectées

[*, 17.0.18)

Correctif

17.0.18

Publication

25/04/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités