CVE-2023-0993 is a Missing Authorization vulnerability affecting the Shield Security plugin for WordPress, specifically versions up to and including 17.0.17. This flaw allows authenticated attackers to inject arbitrary audit log entries, falsely indicating theme or plugin edits, and can also be leveraged for Cross-Site Scripting (XSS) in conjunction with CVE-2023-0992. Rated as MEDIUM severity with a CVSS score of 4.3, the vulnerability has a low attack complexity and requires authenticated access, but does not necessitate user interaction. The primary impact is a compromise of audit log integrity and potential for XSS, leading to information manipulation and client-side attacks. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, or entries in ExploitDB. The vulnerability has garnered minimal community discussion and media coverage, suggesting low public awareness and a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 17.0.17CPE matchmatch criteria | cpe:2.3:a:getshieldsecurity:shield_security:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.