Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-6989

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.635
EPSS Ranking 98.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-6989


Contact Us

Shodan ® - All rights reserved