9.8
CVSSv3

CVE-2023-6989

Published: 05/02/2024 Updated: 13/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated malicious user to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

getshieldsecurity shield security

Vendor Advisories

Check Point Reference: CPAI-2023-1541 Date Published: 28 Feb 2024 Severity: Critical ...