cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-simple-firewall wp-simple-firewall

Direction: ascending
Jun 07, 2024

Shield Security – Smart Bot Blocking & Intrusion Prevention Security # CVE-2024-22163

CVE, Research URL

CVE-2024-22163

Date
Jan 31, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shield Security Shield Security – Smart Bot Blocking & Intrusion Prevention Security allows Stored XSS.This issue affects Shield Security – Smart Bot Blocking & Intrusion Prevention Security: from n/a through 18.5.7.
Affected versions
max 18.5.8.
Status
vulnerable

Shield Security – Smart Bot Blocking & Intrusion Prevention Security # CVE-2023-0992

CVE, Research URL

CVE-2023-0992

Date
Jun 09, 2023
Research Description
The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 17.0.18.
Status
vulnerable

Shield Security – Smart Bot Blocking & Intrusion Prevention Security # CVE-2022-0211

CVE, Research URL

CVE-2022-0211

Date
Feb 21, 2022
Research Description
The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Affected versions
max 13.0.6.
Status
vulnerable

Shield Security – Smart Bot Blocking & Intrusion Prevention Security # CVE-2024-4344

CVE, Research URL

CVE-2024-4344

Date
Jun 02, 2024
Research Description
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.1.13. This is due to missing or incorrect nonce validation on the exec function. This makes it possible for unauthenticated attackers to disable pin protection for the admin interface of the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 19.1.11.
Status
vulnerable

Shield Security – Smart Bot Blocking & Intrusion Prevention Security # CVE-2023-6989

CVE, Research URL

CVE-2023-6989

Date
Feb 06, 2024
Research Description
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
Affected versions
max 18.5.10.
Status
vulnerable

Shield Security – Smart Bot Blocking & Intrusion Prevention Security # CVE-2023-0993

CVE, Research URL

CVE-2023-0993

Date
Jun 09, 2023
Research Description
The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action in versions up to, and including, 17.0.17. This allows authenticated attackers to add arbitrary audit log entries indicating that a theme or plugin has been edited, and is also a vector for Cross-Site Scripting via CVE-2023-0992.
Affected versions
max 17.0.18.
Status
vulnerable
Aug 28, 2024

Shield Security – Smart Bot Blocking & Intrusion Prevention Security # CVE-2024-7313

CVE, Research URL

CVE-2024-7313

Date
Aug 26, 2024
Research Description
The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected versions
max 20.0.6.
Status
vulnerable
Jan 28, 2026

Shield Security – Smart Bot Blocking & Intrusion Prevention Security # CVE-2025-15370

CVE, Research URL

CVE-2025-15370

Date
Jan 16, 2026
Research Description
The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 21.0.9 via the MfaGoogleAuthToggle class due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable Google Authenticator for any user.
Affected versions
max 21.0.10.
Status
vulnerable